Description
An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.
Remediation
References
https://github.com/Wechat-Group/weixin-java-tools/issues/889
Related Vulnerabilities
CVE-2023-40814 Vulnerability in maven package org.opencrx:opencrx-core-models
CVE-2022-36096 Vulnerability in maven package org.xwiki.platform:xwiki-platform-index-ui
CVE-2019-10744 Vulnerability in npm package lodash
CVE-2022-36899 Vulnerability in maven package com.compuware.jenkins:compuware-ispw-operations