CVE-2020-11885

EUVD-2020-4224
WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
mitreCNA
4 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.0/AC:H/AV:N/A:L/C:L/I:N/PR:H/S:C/UI:R