CVE-2020-24589
70Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.1epss 27%
from disclosure to weapon
Published on NVDAug 21
VulnCheck+1249d
exploitation probability
27%top 2% of all CVEs
observed exploitation
yesVulnCheck
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:N/PR:N/S:U/UI:N
Affected products
n/a · n/a