CVE-2020-24589
CRITICAL EXPLOITED NUCLEIWSO2 API Manager < 3.1.0 and API Microgateway 2.2.0 - XML External Entity Injection
Title source: llmExploitation Summary
CVE-2020-24589 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.
Description
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
Nuclei Templates (1)
WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection
CRITICALby lethargynavigator
Shodan:
http.favicon.hash:1398055326
FOFA:
icon_hash=1398055326
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0742
Scores
CVSS v3
9.1
EPSS
0.2694
EPSS Percentile
97.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Details
VulnCheck KEV
2024-01-22
CWE
CWE-611
Status
published
Products (2)
wso2/api_manager
< 3.1.0
wso2/api_microgateway
2.2.0
Published
Aug 21, 2020
Tracked Since
Feb 18, 2026