Product
MPXJ is vulnerable to an XML External Entity (XXE) injection flaw via the MerlinReader component when processing XML content within the ZTIMEINTERVALS column of Merlin project SQLite files, allowing for arbitrary file reads.