Security Advisories (1)
CPANSA-XML-Simple-2018-01 (2018-02-18)

The No. 4 item on the OWASP top 10 is external XML entities. When using XML::Parser, XML::Simple is currently vulnerable by default.

Changes for version 2.24 - 2017-04-17

  • fix typo in last commit with mistakenly removed some underscores
  • don't initialise $XML::Simple::PREFERRED_PARSER to undef as a caller may have already set it before loading XML::Simple and if not, it would have defaulted to undef anyway (RT#118205 from Slaven Rezić)

Documentation

Frequently Asked Questions about XML::Simple

Modules

An API for simple XML files