CVE ID(s)
Report
OWASP on XPath Injection:
XPath Injection attacks occur when a web site uses user-supplied information to construct an XPath query for XML data. By sending intentionally malformed information into the web site, an attacker can find out how the XML data is structured, or access data that he may not normally have access to.
github/codeql-go#66
CVE ID(s)
Report
OWASP on XPath Injection:
github/codeql-go#66