PT-2022-11556 · Eyoucms · Eyoucms
Published
2022-03-20
·
Updated
2022-03-29
·
CVE-2021-42194
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EyouCms version 1.5.4-UTF8-SP3
Description
The issue arises from the
wechat return function in /controller/Index.php, which passes user input directly into the simplexml load string function without prohibiting external entities. This triggers a XML external entity (XXE) injection issue.Recommendations
For EyouCms version 1.5.4-UTF8-SP3, consider modifying the
wechat return function to properly sanitize user input before passing it to the simplexml load string function, or apply configuration changes to prohibit external entities.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eyoucms