Critical
CVE-2020-24589
PUBLISHEDThe Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
Not yet in CISA KEV
- Vendor
- WSO2
- Product
- API Manager
- Published
- Aug 21, 2020
- EPSS
- —
Automate This Intelligence with the Pro API
Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.
Description
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
CVSS Scores
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:N/PR:N/S:U/UI:N
Exploitation Status
Exploited in the wild
Recorded 2025-06-25 00:00:00 UTC · The Shadowserver (via CIRCL)
Proof of concept available
Recorded 2026-06-12 14:20:16 UTC · Nuclei Templates
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| The Shadowserver (via CIRCL) First | 2025-06-25 00:00 UTC |
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-24589.yaml | Apr 25, 2025 |
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
nuclei · Created Unknown
Timeline
-
Proof of Concept Exploit Available
-
Added to KEVIntel
-
Detected by Nuclei
-
CVE Published to Public
-
CVE ID Reserved