An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows malicious users to access sensitive database information via a crafted SVG file.
magicpin magicpin 3.4