XML External Entity Injection Vulnerability in EyouCms by EyouCMS
CVE-2021-42194
7.2HIGH
Summary
The wechat_return function in the Index.php controller of EyouCms V1.5.4-UTF8-SP3 directly incorporates user input into the simplexml_load_string function. This unsanitized user input can lead to an XML External Entity (XXE) injection vulnerability, allowing attackers to potentially access internal files and execute malicious code. It is crucial for users to apply security patches or updates to mitigate the risks associated with this type of vulnerability.
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved