pkp pkp-lib XSLTransformer.php _transformPHP xml external entity reference
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.1epss 0.3%
probabilidad de explotación
0.3%top 73% de las CVE
explotación observada
noninguna fuente lo reporta
A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _transformPHP of the file classes/xslt/XSLTransformer.php. The manipulation results in xml external entity reference. The attack can be executed remotely. Upgrading to version 3.3.0-23, 3.4.0-11 and 3.5.0-5 is sufficient to fix this issue. The patch is identified as 78c699370ea43ae2784e1c4ace7c947d207f2b47. Upgrading the affected component is advised.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
Productos afectados
pkp · pkp-libReferencias
https://github.com/pkp/pkp-lib/https://github.com/pkp/pkp-lib/commit/78c699370ea43ae2784e1c4ace7c947d207f2b47https://github.com/pkp/pkp-lib/issues/12977https://github.com/pkp/pkp-lib/releases/tag/3_5_0-5https://vuldb.com/cve/CVE-2026-76572https://vuldb.com/submit/878359https://vuldb.com/vuln/393037https://vuldb.com/vuln/393037/cti