Description
An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.
Remediation
References
https://github.com/Wechat-Group/weixin-java-tools/issues/889
Related Vulnerabilities
CVE-2022-29647 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2023-30514 Vulnerability in maven package org.jenkins-ci.plugins:azure-keyvault
CVE-2023-33246 Vulnerability in maven package org.apache.rocketmq:rocketmq-controller
CVE-2020-36184 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2013-6397 Vulnerability in maven package org.apache.solr:solr-core