PT-2022-11556 · Eyoucms · Eyoucms

Published

2022-03-20

·

Updated

2022-03-29

·

CVE-2021-42194

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EyouCms version 1.5.4-UTF8-SP3
Description The issue arises from the wechat return function in /controller/Index.php, which passes user input directly into the simplexml load string function without prohibiting external entities. This triggers a XML external entity (XXE) injection issue.
Recommendations For EyouCms version 1.5.4-UTF8-SP3, consider modifying the wechat return function to properly sanitize user input before passing it to the simplexml load string function, or apply configuration changes to prohibit external entities. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42194

Affected Products

Eyoucms