Description
An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.
Remediation
References
https://github.com/Wechat-Group/weixin-java-tools/issues/889
Related Vulnerabilities
CVE-2016-10735 Vulnerability in maven package ru.taskurotta:bootstrap
CVE-2018-3753 Vulnerability in npm package merge-objects
CVE-2020-13959 Vulnerability in maven package org.apache.velocity.tools:velocity-tools-view
CVE-2020-29204 Vulnerability in maven package com.xuxueli:xxl-job-admin
CVE-2019-17570 Vulnerability in maven package org.apache.xmlrpc:xmlrpc