PT-2019-17575 · Weechat · Weixin-Java-Tools
Published
2019-01-04
·
Updated
2025-09-12
·
CVE-2019-5312
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
weixin-java-tools version 3.3.0
Description
An issue exists in the getXmlDoc method of the BaseWxPayResult.java file, which contains an XXE vulnerability. This issue is a result of an incomplete fix.
Recommendations
For weixin-java-tools version 3.3.0, consider disabling the
getXmlDoc method in the BaseWxPayResult.java file as a temporary workaround until a patch is available. Restrict access to the BaseWxPayResult.java file to minimize the risk of exploitation.Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Weixin-Java-Tools