First published: Sun Jul 08 2018(Updated: )
WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.github.wxpay:wxpay-sdk | <=3 | |
Tencent Wechat Pay |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13439 is a vulnerability found in WXPayUtil in WeChat Pay Java SDK that allows XXE attacks involving a merchant notification URL.
CVE-2018-13439 has a severity rating of 7.5 out of 10 (high).
The affected software of CVE-2018-13439 includes the WeChat Pay Java SDK (version 3) and Tencent Wechat Pay.
XXE attacks involving a merchant notification URL exploit CVE-2018-13439 by using XML external entities to access arbitrary files or execute remote code.
You can find more information about CVE-2018-13439 on the NIST NVD website, Packet Storm Security, and GitHub advisory.