Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c49v-35ff-q9f7

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

DotPlant2 Improper Restriction of XML External Entity Reference

An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Пакеты

Наименование

devgroup/dotplant

composer
Затронутые версииВерсия исправления

< 2020-09-14

2020-09-14

EPSS

Процентиль: 58%
0.0036
Низкий

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

EPSS

Процентиль: 58%
0.0036
Низкий

7.5 High

CVSS3

Дефекты

CWE-611