CVE-2019-11519

Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen.
Configurations

Configuration 1

cpe:2.3:a:nopcommerce:nopcommerce:*:*:*:*:*:*:*:*

Information

Published : 2019-04-25 01:29

Updated : 2019-05-01 07:03


NVD link : CVE-2019-11519

Mitre link : CVE-2019-11519

Products Affected
No products.
CWE
CWE-611

Improper Restriction of XML External Entity Reference