Description
An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.
Remediation
References
https://github.com/Wechat-Group/weixin-java-tools/issues/889
Related Vulnerabilities
CVE-2020-7674 Vulnerability in npm package access-policy
CVE-2022-25847 Vulnerability in npm package serve-lite
CVE-2020-28500 Vulnerability in maven package org.webjars.npm:lodash
CVE-2020-7643 Vulnerability in npm package paypal-adaptive
CVE-2023-46657 Vulnerability in maven package org.jenkins-ci.plugins:gogs-webhook