CVE-2020-11885

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
17/04/2020
Last modified:
21/07/2021

Description

WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wso2:enterprise_integrator:*:*:*:*:*:*:*:* 6.6.0 (including)