6.5
CVE-2025-60833
- EPSS 0.13%
- Veröffentlicht 08.10.2025 00:00:00
- Zuletzt bearbeitet 10.10.2025 16:16:13
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying crafted XML data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ghostxbh ≫ Uzy-ssm-mall Version1.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.328 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-91 XML Injection (aka Blind XPath Injection)
The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.