CVE-2026-12788
Received Received - Intake
XML External Entity Injection in Zhilink ADP Application Developer Platform

Publication date: 2026-06-21

Last updated on: 2026-06-21

Assigner: VulDB

Description
A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerability affects unknown code of the file /adpweb/a/base/barcodeDetail/import of the component XML Parser. This manipulation causes xml external entity reference. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-21
Last Modified
2026-06-21
Generated
2026-06-21
AI Q&A
2026-06-21
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
zhilink adp_application_developer_platform 1.0.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CWE-610 The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the zhilink ADP Application Developer Platform version 1.0.0, specifically in the XML Parser component within the file /adpweb/a/base/barcodeDetail/import. It is an XML External Entity (XXE) vulnerability, which means that the XML parser can be manipulated to process external entity references. This manipulation can be initiated remotely, allowing an attacker to exploit the system by sending crafted XML data.

Impact Analysis

The vulnerability allows remote attackers to exploit the XML parser by injecting external entity references. This can lead to unauthorized access to sensitive data, denial of service, or other impacts depending on how the XML data is processed by the application. Since the exploit has been publicly disclosed and the vendor has not responded, the risk of exploitation is higher.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12788. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart