Описание
An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted XML file.
EPSS
Процентиль: 40%
0.00182
Низкий
8.1 High
CVSS3
Дефекты
CWE-91
Связанные уязвимости
CVSS3: 6.1
github
11 месяцев назад
An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted XML file.
EPSS
Процентиль: 40%
0.00182
Низкий
8.1 High
CVSS3
Дефекты
CWE-91