Record summary

CVE-2020-24589 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWSO2 API Manager <=3.1.0 - Blind XML External Entity InjectionCVSS 9.1

WSO2 API Manager 3.1.0 and earlier is vulnerable to blind XML external entity injection (XXE). XXE often allows an attacker to view files on the server file system, and to interact with any backend or external systems that the application itself can access which allows the attacker to transmit sensitive data from the compromised server to a system that the attacker controls.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information, denial of service, or server-side request forgery.

Remediation

Upgrade to a patched version of WSO2 API Manager (3.1.1 or above) or apply the provided security patch.

WeaknessesCWE-611
Authorslethargynavigator
Template tagscve2020cvewso2xxeoastblindvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CPE: cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:1398055326
FOFA: icon_hash=1398055326
Google: inurl:"carbon/admin/login"

Source: ProjectDiscovery

References

2