Executive brief
Zhilink ADP Application Developer Platform, a tool used for building and managing business applications, contains a security flaw in its XML processing component. An attacker can exploit this to read sensitive files from the server or potentially disrupt internal services. This could lead to the exposure of confidential configuration data or unauthorized access to internal network resources.
Technical details
An XML External Entity (XXE) vulnerability exists in Zhilink ADP Application Developer Platform 1.0.0 within the XML Parser component. The flaw is located in the file /adpweb/a/base/barcodeDetail/import, where the application fails to properly restrict external entity references in user-supplied XML input. A remote attacker with low privileges can exploit this by submitting a specially crafted XML file to initiate an attack. Successful exploitation allows for the disclosure of local files, internal port scanning, or Server-Side Request Forgery (SSRF). While the vendor was notified, no patch has been confirmed at this time.
Affected products
- zhilink (智互联) ADP Application Developer Platform (应用开发者平台) 1.0.0
Timeline
- 2026-06-21: advisory: Vulnerability published by VulDB/NVD
- 2026-06-21: disclosed: Exploit details publicly disclosed