← back
CVE-2020-24589criticalobserved exploitation

CVE-2020-24589

70Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.1epss 27%
from disclosure to weapon
Published on NVDAug 21
VulnCheck+1249d
exploitation probability
27%top 2% of all CVEs
observed exploitation
yesVulnCheck
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:N/PR:N/S:U/UI:N
Affected products
n/a · n/a