在 pkp-lib 3.3.0-22 及更早版本、3.4.0-10 及更早版本、以及 3.5.0-4 及更早版本中发现了一个漏洞。受影响的元素是文件 classes/xslt/XSLTransformer.php 中的 _transformPHP 函数。该漏洞可导致 XML 外部实体引用(XXE)问题。攻击者可远程执行该漏洞。将受影响组件升级至版本 3.3.0-23、3.4.0-11 或 3.5.0-5 即可修复此问题。相关补丁标识为 78c699370ea43ae2784e1c4ace7c947d207f2b47
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet