XXE Code Execution Vulnerability in Yimioa Before v2024.07.04
An XML external entity (XXE) injection vulnerability exists in the /weixin/aes/XMLParse.java component of yimioa before version 2024.07.04. This vulnerability enables attackers to execute arbitrary code by providing a carefully crafted XML file. The issue affects the software's XML parsing mechanism, which can be manipulated to perform unauthorized actions.