Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hanqing-Sun

#25091of 53,630
9.8Total CVSS
Vulnerabilities · 1
PT-2023-10823
9.8
2023-03-21
Unknown · Wechat Sdk · CVE-2018-25082
**Name of the Vulnerable Software and Affected Versions** zwczou WeChat SDK Python versions 0.3.0 through 0.5.4 **Description** A critical issue affects the `validate/to xml` function, leading to xml external entity reference. The attack may be initiated remotely. **Recommendations** To address this issue, upgrade to version 0.5.5. As a temporary workaround, consider disabling the `validate/to xml` function until the patch is applied. Restrict access to the affected component to minimize the risk of exploitation.