{"id":"GHSA-2g98-f9jv-w8c5","summary":"robrichards/xmlseclibs XPath injection","details":"A vulnerability has been identified in the robrichards/xmlseclibs library, specifically related to XPath injection. The issue arises from inadequate filtering of user input before it is incorporated into XPath expressions.","modified":"2024-12-05T05:40:08.868202Z","published":"2024-05-20T18:06:52Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-20T18:06:52Z","nvd_published_at":null,"cwe_ids":["CWE-91"]},"references":[{"type":"WEB","url":"https://github.com/robrichards/xmlseclibs/commit/649032643f7aac493e91ca318da0339aec72aa4a"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/robrichards/xmlseclibs/2018-09-27.yaml"},{"type":"PACKAGE","url":"https://github.com/robrichards/xmlseclibs"}],"affected":[{"package":{"name":"robrichards/xmlseclibs","ecosystem":"Packagist","purl":"pkg:composer/robrichards/xmlseclibs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"3.0.2"}]}],"versions":["1.3.2","1.3.3","1.3.4","1.4.0","1.4.1","1.4.2","1.4.3","2.0.0","2.0.1","2.1.0","2.1.1","3.0.0","3.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-2g98-f9jv-w8c5/GHSA-2g98-f9jv-w8c5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}