S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-24589 Scanner

CVE-2020-24589 scanner - XML External Entity (XXE) vulnerability in Management Console in WSO2 API Manager and API Microgateway

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-24589
9.1
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

WSO2 API Manager is an open-source platform for managing APIs and is widely used by businesses to ensure secure and efficient integration of applications. API Microgateway, on the other hand, is a lightweight and highly scalable solution that enables businesses to take control of their APIs. Both these tools are widely used for managing APIs across different environments, such as cloud-based and on-premises.

However, WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 has been found to have a vulnerability code named CVE-2020-24589. This vulnerability is related to XML External Entity injection (XXE) attacks. XXE is a type of attack that enables hackers to inject malicious code into an XML document, allowing them to gain unauthorized access to sensitive data.

If this vulnerability is exploited, it can lead to various types of attacks, such as denial-of-service (DoS) attacks, server-side request forgery (SSRF), and access to sensitive information. The hackers can use this vulnerability to gain access to confidential information, such as login credentials, intellectual property, and other sensitive data.

Thanks to pro features like security assessments and security reports available on s4e.io, users can easily and quickly learn about vulnerabilities in their digital assets. The platform provides a comprehensive and reliable security assessment tool that enables users to identify and address vulnerabilities in their digital assets with ease. Users can also receive regular security reports that contain valuable insights about the performance of their security measures and identify any areas that need improvement.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Restrict the use of XML and limit its access to only trusted users
  • Disable the use of external entities in XML entities
  • Verify that XML documents are parsed correctly and do not contain any malicious code
  • Constantly monitor and evaluate XML inputs in the system

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.