mpxj is vulnerable to Path Traversal
53
Medium Risk
MPXJ extracts Primavera P3 PRX and SureTrak STX schedule files into a temporary directory using embedded filenames without checking that the resulting path stays inside that directory. A crafted file can supply names that escape the temp dir (SureTrak STX names are long enough for classic traversal). Before the fix, reading such a file could write to arbitrary filesystem locations. The fix rejects extracted paths that leave the target directory.
You are affected if you are using a version that falls within the vulnerable range and you use MPXJ to read untrusted Primavera P3 PRX or SureTrak STX files.
mpxj is vulnerable to Path Traversal in versions 7.3.0 - 16.4.1.
Upgrade the net.sf.mpxj:mpxj library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant