Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DotPlant2 代码问题漏洞
Vulnerability Description
DotPlant2DotPlant2,DotPlant2是俄罗斯的一个免费的用于购物的CMS系统。 DotPlant2 2020-09-14版本之前存在安全漏洞。该漏洞源于payment/Pay2PayPayment.php中的Pay2PayPayment类,用户输入($_POST[xml])用于未经过滤的simplexml_load_string。
CVSS Information
N/A
Vulnerability Type
N/A