MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
https://www.tenable.com/blog/oracle-january-2021-critical-patch-update-five-critical-weblogic-flaws-cve-2021-2109
https://www.oracle.com/security-alerts/cpujan2021.html
https://github.com/joniles/mpxj/pull/178/commits/c3e457f7a16facfe563eade82b0fa8736a8c96f9
Source: Mitre, NVD
Published: 2020-08-29
Updated: 2024-11-21
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical