Medium severity4.9OSV Advisory· Published Apr 25, 2019· Updated Jun 17, 2026
CVE-2019-11519
CVE-2019-11519
Description
Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2release-1.70, release-1.80, release-1.90, …+ 1 more
- (no CPE)range: release-1.70, release-1.80, release-1.90, …
- (no CPE)range: <=4.10
Patches
Vulnerability mechanics
References
2- github.com/nopSolutions/nopCommerce/issues/3713nvdIssue TrackingPatchThird Party Advisory
- www.nopcommerce.com/boards/t/62390/xxe-version-390.aspxnvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.