Description
An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.
Remediation
References
https://github.com/Wechat-Group/weixin-java-tools/issues/889
Related Vulnerabilities
CVE-2020-7639 Vulnerability in npm package @eivifj/dot
CVE-2022-24802 Vulnerability in npm package deepmerge-ts
CVE-2010-1244 Vulnerability in maven package org.apache.activemq:activemq-web
CVE-2022-24891 Vulnerability in maven package org.owasp.esapi:esapi
CVE-2013-6357 Vulnerability in maven package tomcat:catalina