PT-2019-17575 · Weechat · Weixin-Java-Tools

Published

2019-01-04

·

Updated

2025-09-12

·

CVE-2019-5312

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions weixin-java-tools version 3.3.0
Description An issue exists in the getXmlDoc method of the BaseWxPayResult.java file, which contains an XXE vulnerability. This issue is a result of an incomplete fix.
Recommendations For weixin-java-tools version 3.3.0, consider disabling the getXmlDoc method in the BaseWxPayResult.java file as a temporary workaround until a patch is available. Restrict access to the BaseWxPayResult.java file to minimize the risk of exploitation.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-5312
GHSA-H755-H99P-9FFV

Affected Products

Weixin-Java-Tools