Advantech · Advantech Wise-Paas/Rmm · CVE-2019-18227
**Name of the Vulnerable Software and Affected Versions**
Advantech WISE-PaaS/RMM versions 3.3.29 and prior
**Description**
The issue concerns XML External Entity (XXE) vulnerabilities that may allow the disclosure of sensitive data. Multiple components within Advantech WISE-PaaS/RMM are affected, including WechatSignin, RecoveryMgmt, and AccountMgmt, where various XML External Entity Processing Information Disclosure Vulnerabilities exist. These vulnerabilities can be exploited through different endpoints and parameters, potentially leading to the disclosure of sensitive information.
**Recommendations**
For Advantech WISE-PaaS/RMM versions 3.3.29 and prior, update to a version later than 3.3.29 to resolve the issue.
As a temporary workaround, consider restricting access to the affected components, such as WechatSignin, RecoveryMgmt, and AccountMgmt, until a patch is available.
Avoid using the vulnerable XML External Entity processing functionality in the affected components until the issue is resolved.