← Back to CVE List

CVE-2019-12415

Published: 2019-10-23T20:15Z
Last Modified: 2024-11-21T04:22Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt