Description
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server Uncontrolled Recursion Vulnerability (CVE-2021-42717)
WordPress Plugin FeedWordPress Cross-Site Scripting (2014.0805)
WordPress Plugin wpShopGermany Free Arbitrary File Upload (4.0.10)
WordPress Plugin NextGEN Gallery-WordPress Gallery 'Gallery Path' Field Cross-Site Scripting (1.9.5)