{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amogublogmogublog/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mogublog:mogublog:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-89260"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MoguBlog (\u003c= 6.2)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xxe","injection"],"_cs_type":"advisory","_cs_vendors":["MoguBlog"],"content_html":"\u003cp\u003eMoguBlog versions through 6.2 contain a critical XML external entity (XXE) injection vulnerability located within the WeChat callback handler. The flaw exists in the \u003ccode\u003eWechatRestApi.index()\u003c/code\u003e method, which improperly handles raw request bodies by passing them to the \u003ccode\u003eSignUtil.xmlToMap()\u003c/code\u003e function. This function utilizes a \u003ccode\u003edom4j\u003c/code\u003e SAXReader without explicitly disabling Document Type Definition (DTD) processing or external entity expansion. Consequently, unauthenticated remote attackers can supply malicious XML payloads containing crafted DOCTYPE declarations to the \u003ccode\u003e/wechat/wechatCheck\u003c/code\u003e endpoint. Successful exploitation allows for the exfiltration of local system files, the execution of unauthorized outbound HTTP requests (SSRF), and potential reflection of resolved entities within application error messages. This vulnerability poses a significant risk to the confidentiality and integrity of the application server.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker crafts a malicious XML payload including a DOCTYPE declaration defining an external entity pointing to a local file (e.g., /etc/passwd) or a target URL.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a POST request targeting the \u003ccode\u003e/wechat/wechatCheck\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eWechatRestApi.index()\u003c/code\u003e method accepts the raw request body.\u003c/li\u003e\n\u003cli\u003eThe application triggers the \u003ccode\u003eSignUtil.xmlToMap()\u003c/code\u003e method, which initiates a \u003ccode\u003edom4j\u003c/code\u003e SAXReader to parse the incoming request.\u003c/li\u003e\n\u003cli\u003eThe unhardened XML parser processes the malicious DOCTYPE, resolving the external entity.\u003c/li\u003e\n\u003cli\u003eThe application includes the content of the external entity or the response from the SSRF request in the HTTP error response.\u003c/li\u003e\n\u003cli\u003eThe attacker parses the returned data to view sensitive local files or capture the output of unauthorized outbound requests.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-89260 allows unauthenticated attackers to gain unauthorized access to sensitive files on the host filesystem and utilize the application as a proxy for server-side request forgery (SSRF) attacks. This can lead to the exposure of credentials, configuration files, or internal network mapping.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate MoguBlog to a patched version beyond 6.2 immediately upon availability from the vendor.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect POST requests to the \u003ccode\u003e/wechat/wechatCheck\u003c/code\u003e endpoint containing suspicious XML entity patterns.\u003c/li\u003e\n\u003cli\u003eConfigure the application server or WAF to inspect and block inbound HTTP requests containing \u003ccode\u003e!DOCTYPE\u003c/code\u003e or \u003ccode\u003eENTITY\u003c/code\u003e tags when targeting the identified callback URL.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-11T17:14:41Z","date_published":"2026-09-11T17:14:32Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mogublog-xxe/","summary":"MoguBlog versions through 6.2 are vulnerable to unauthenticated XML External Entity (XXE) injection via the WeChat callback handler, allowing arbitrary file read and outbound SSRF.","title":"MoguBlog XML External Entity Injection in WeChat Callback","url":"https://feed.craftedsignal.io/briefs/2026-09-mogublog-xxe/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:mogublog:mogublog:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}