Описание
An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Ссылки
- ExploitPatchThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2020-09-14 (исключая)
cpe:2.3:a:dotplant:dotplant2:*:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.0036
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-611
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
DotPlant2 Improper Restriction of XML External Entity Reference
EPSS
Процентиль: 58%
0.0036
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-611