Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2024-3572
Description:The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate network connections, or circumvent firewalls by submitting specially crafted XML data.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2024-3572
https://github.com/scrapy/scrapy/commit/809bfac4890f75fc73607318a04d2ccba71b3d9f
https://github.com/scrapy/scrapy/commit/809bfac4890f75fc73607318a04d2ccba71b3d9f
https://huntr.com/bounties/c4a0fac9-0c5a-4718-9ee4-2d06d58adabb
https://huntr.com/bounties/c4a0fac9-0c5a-4718-9ee4-2d06d58adabb




© 1998-2025 E-Soft Inc. All rights reserved.