CVE-2020-24589

CRITICAL EXPLOITED NUCLEI

WSO2 API Manager < 3.1.0 and API Microgateway 2.2.0 - XML External Entity Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-24589 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.

Nuclei Templates (1)

WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection
CRITICALby lethargynavigator
Shodan: http.favicon.hash:1398055326
FOFA: icon_hash=1398055326

References (1)

Core 1
Core References

Scores

CVSS v3 9.1
EPSS 0.2694
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Details

VulnCheck KEV 2024-01-22
CWE
CWE-611
Status published
Products (2)
wso2/api_manager < 3.1.0
wso2/api_microgateway 2.2.0
Published Aug 21, 2020
Tracked Since Feb 18, 2026