{"id":"GHSA-c49v-35ff-q9f7","summary":"DotPlant2 Improper Restriction of XML External Entity Reference","details":"An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.","aliases":["CVE-2020-25750"],"modified":"2024-04-22T19:41:55.295535Z","published":"2022-05-24T17:29:01Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-04-22T19:00:49Z","nvd_published_at":"2020-09-18T04:15:00Z","cwe_ids":["CWE-611"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25750"},{"type":"WEB","url":"https://github.com/DevGroup-ru/dotplant2/issues/400"},{"type":"WEB","url":"https://github.com/DevGroup-ru/dotplant2/commit/fee86c7052c227762c7325eb5c2811d9323f8429"}],"affected":[{"package":{"name":"devgroup/dotplant","ecosystem":"Packagist","purl":"pkg:composer/devgroup/dotplant"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2020-09-14"}]}],"versions":["0.0.1","0.0.2","0.0.3","0.0.4","1.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-c49v-35ff-q9f7/GHSA-c49v-35ff-q9f7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}