← Retour aux CVEs
CVE-2024-8010
LOW3.5
Description
The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the unescaped external entity references. By leveraging this vulnerability, a malicious actor can read confidential files from the product's file system or access limited HTTP resources reachable via HTTP GET requests to the vulnerable product.
Details CVE
Score CVSS v3.13.5
SeveriteLOW
Vecteur CVSSCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vecteur d'attaqueADJACENT_NETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie4/16/2026
Derniere modification4/17/2026
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-611
References
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3581/(ed10eef1-636d-4fbe-9993-6890dfa878f8)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.