Vulnerabilities > CVE-2019-9761 - XXE vulnerability in PHPshe 1.7
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authentication. This occurs because of the call to wechat_getxml in include/plugin/payment/wechat/notify_url.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |