XML External Entity Vulnerability in Zhilink ADP Application Developer Platform
CVE-2026-12788
Key Information:
- Vendor
Zhilink 智互联(深圳)科技有限公司
- Vendor
- CVE Published:
- 21 June 2026
Badges
What is CVE-2026-12788?
A vulnerability has been identified in the Zhilink (Shenzhen) Technology Co., Ltd. ADP Application Developer Platform version 1.0.0. This issue arises from the XML Parser component's handling of external entity references in the file /adpweb/a/base/barcodeDetail/import. An attacker could exploit this vulnerability remotely to manipulate XML structures, potentially leading to unauthorized data access or system compromise. Despite initial contact with the vendor about this issue, no response was received, leading to concerns regarding the security measures in place.
Affected Version(s)
ADP Application Developer Platform 应用开发者平台 1.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
