XXE in WeChat Pay SDK

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Background “Mobile payments surge to $9 trillion a year, changing how people shop, borrow—even panhandle”, as WSJ.com once reported. As a payment security researcher, I occasionally found a perilous problem about WeChat Pay which I think may be esay to make use of. Therefore, I hope to be able to contact with WeChat Pay quickly. ### Description When using WeChat payment merchants need providing a notification URL to accept asynchronous payment results. Unfortunately, WeChat unintentionally provides a xxe vulnerability in the JAVA version SDK which handles this result. The attacker can build malicious payload towards the notification URL to steal any information of the merchant server as he or she want. Once the attacker get the crucial security key (md5-key and merchant-Id etc.) of the merchant , he can even buy anything without paying by just sending forged info to deceive the merchants. WeChat can fix it by updating the SDK quite easily, however the bad side is while exposing...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息