Impact
MoguBlog versions up to 6.2 are vulnerable to an XML External Entity injection in the WeChat callback endpoint. The application passes the raw request body to a SAX parser that does not enforce DTD or external‑entity restrictions. An attacker who can send XML to /wechat/wechatCheck can embed DOCTYPE declarations that reference local files or remote resources, causing the server to read arbitrary files or initiate outbound HTTP requests. The resolved entities are reflected in error responses, providing acknowledgement of successful exploitation and giving the attacker the ability to read file contents or confirm reachability of external hosts.
Affected Systems
MoguBlog by moxi624, all releases up to and including 6.2 are affected. Any installation running 6.2 or earlier is susceptible.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the vulnerability is exploitable by unauthenticated remote actors who can craft XML payloads to the WeChat callback endpoint. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication requirement and the clear exploitation path make this a significant risk for exposed deployments.
OpenCVE Enrichment