Vulnerability CVE-2021-42194


Published: 2022-03-20   Modified: 2022-03-21

Description:
The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (XXE) injection vulnerability.

 References:
https://github.com/eyoucms/eyoucms/issues/19

Copyright 2026, cxsecurity.com

 

Back to Top