An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying crafted XML data.
References
| Link | Resource |
|---|---|
| https://gist.github.com/ChangeYourWay/1364b9e78490ebd5cd31bcdc105a914f | Third Party Advisory |
| https://github.com/ChangeYourWay/post/blob/main/uzy-ssm-mall.md | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-10-08 14:15
Updated : 2025-10-10 16:16
NVD link : CVE-2025-60833
Mitre link : CVE-2025-60833
CVE.ORG link : CVE-2025-60833
JSON object : View
Products Affected
ghostxbh
- uzy-ssm-mall
CWE
CWE-91
XML Injection (aka Blind XPath Injection)
