Ywoa XML External Entity Reference Vulnerability in WXCallBack Interface

Vulnerability

A vulnerability allowing XML external entity (XXE) injection has been identified in Ywoa versions prior to 2024.07.03. This issue arises in the WXCallBack interface, specifically within the XMLParse.java file, where the extract function improperly handles XML data. The vulnerability can be exploited remotely, potentially leading to unauthorized access or manipulation of XML data.

Impact

Exploitation of this vulnerability allows for XML external entity injection, which can be used to read sensitive files on the server or perform a denial-of-service attack by causing the application to hang or crash.

Remediation

Users are advised to upgrade to Ywoa version 2024.07.04 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.8
exploitability
6.0
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.