Insecure File Writing Vulnerability in MPXJ Library by Joniles
CVE-2024-49771

Currently unrated

Key Information:

Vendor

Joniles

Status
Vendor
CVE Published:
28 October 2024

What is CVE-2024-49771?

The MPXJ library, which facilitates reading and writing project plans across various formats, is susceptible to an insecure file writing vulnerability. An incomplete patch for a previously identified issue allows attackers to potentially manipulate paths, which can result in files being written to unauthorized locations. This risk highlights the importance of upgrading to MPXJ version 13.5.1, which addresses the vulnerability, safeguarding both users and systems that rely on this library.

References

Timeline

  • Vulnerability published

.