CVE-2019-11519
EUVD-2019-319025.04.2019, 13:29
Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nopcommerce | nopcommerce | 𝑥 ≤ 4.10 |
𝑥
= Vulnerable software versions