Description
An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.
Remediation
References
https://github.com/Wechat-Group/weixin-java-tools/issues/889
Related Vulnerabilities
CVE-2017-16007 Vulnerability in npm package node-jose
CVE-2021-26541 Vulnerability in npm package gitlog
CVE-2022-36313 Vulnerability in maven package org.webjars.npm:file-type
CVE-2022-4565 Vulnerability in maven package cn.hutool:hutool-core
CVE-2022-34112 Vulnerability in maven package io.dataease:dataease-plugin-common