CVE-2025-63917
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-17

Last updated on: 2025-11-18

Assigner: MITRE

Description
PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class without disabling external entity resolution, enabling attackers to: Read arbitrary files from the victim's filesystem, exfiltrate sensitive data via out-of-band (OOB) HTTP requests, perform SSRF attacks against internal network resources, or cause a denial of service via entity expansion attacks.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-17
Last Modified
2025-11-18
Generated
2026-05-07
AI Q&A
2025-11-17
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
itext itext *
wmjordan pdfpatcher *
mupdf mupdf *
wmjordan pdfpatcher 1.1.3.4663
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in PDFPatcher's XML bookmark import functionality, which does not restrict XML external entity (XXE) references. Because the application uses .NET's XmlDocument class without disabling external entity resolution, attackers can exploit this to read arbitrary files on the victim's filesystem, exfiltrate sensitive data via out-of-band HTTP requests, perform server-side request forgery (SSRF) attacks against internal network resources, or cause denial of service through entity expansion attacks.


How can this vulnerability impact me? :

The vulnerability can lead to unauthorized access to sensitive files on your system, data leakage through exfiltration of information, potential attacks on internal network resources via SSRF, and denial of service conditions caused by entity expansion attacks, all of which can compromise system security and availability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart