CVE-2020-25750

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
18/09/2020
Last modified:
04/08/2024

Description

An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dotplant:dotplant2:*:*:*:*:*:*:*:* 2020-09-14 (excluding)


References to Advisories, Solutions, and Tools