CVE-2020-11885

HIGH

WSO2 Enterprise Integrator <= 6.6.0 - XML External Entity Injection via XML Validator

Title source: llm
STIX 2.1

Description

WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0078
EPSS Percentile 51.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611 CWE-918
Status published
Products (1)
wso2/enterprise_integrator < 6.6.0
Published Apr 17, 2020
Tracked Since Feb 18, 2026