sowish

2 exploits Active since Mar 2019
CVE-2019-9762 GITEE CRITICAL php WRITEUP
PHPSHE 1.7 - Unauthenticated SQL Injection via Alipay Payment Plugin id Parameter
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication.
48 stars
CVSS 9.8
CVE-2019-9761 GITEE HIGH php WRITEUP
PHPSHE 1.7 - Unauthenticated XML External Entity Injection via wechat_getxml
An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authentication. This occurs because of the call to wechat_getxml in include/plugin/payment/wechat/notify_url.php.
48 stars
CVSS 7.5