Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen.
References
Link Resource
https://github.com/nopSolutions/nopCommerce/issues/3713 Issue Tracking Patch Third Party Advisory
https://www.nopcommerce.com/boards/t/62390/xxe-version-390.aspx Issue Tracking Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-04-25T12:44:48

Updated: 2019-04-25T12:44:48

Reserved: 2019-04-25T00:00:00


Link: CVE-2019-11519

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-04-25T13:29:00.407

Modified: 2019-05-01T19:03:47.610


Link: CVE-2019-11519

JSON object: View

cve-icon Redhat Information

No data.

CWE