Security Advisories (1)
CPANSA-XML-Simple-2018-01 (2018-02-18)

The No. 4 item on the OWASP top 10 is external XML entities. When using XML::Parser, XML::Simple is currently vulnerable by default.

Changes for version 1.04

  • added (optional) OO interface for changing default options
  • added 'keeproot' option (requested by Mark D. Anderson - MDA)
  • added 'contentkey' option (also requested by MDA)
  • incorporated 'forcearray' as arrayref patch from Andrew McNaughton

Modules

Trivial API for reading and writing XML (esp config files)