### [CVE-2022-25236](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25236) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs. ### POC #### Reference - http://packetstormsecurity.com/files/167238/Zoom-XMPP-Stanza-Smuggling-Remote-Code-Execution.html - https://www.oracle.com/security-alerts/cpuapr2022.html #### Github - https://github.com/ARGOeu-Metrics/secmon-probes - https://github.com/ARGOeu/secmon-probes - https://github.com/ARPSyndicate/cvemon - https://github.com/EGI-Federation/SVG-advisories - https://github.com/Satheesh575555/external_expat_AOSP10_r33_CVE-2022-25236 - https://github.com/fokypoky/places-list - https://github.com/nomi-sec/PoC-in-GitHub