ZeroHour

CVE-2019-9761

PoC
CVSS 3.0
7.5 high
EPSS
2%p76
Published
()
Modified
Description

An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authentication. This occurs because of the call to wechat_getxml in include/plugin/payment/wechat/notify_url.php.

Vendors
phpshe
Products
phpshe
Weakness
CWE-611
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.