CVE-2024-6893 | Journyx Unauthenticated XML External Entities Injection
Exp
The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.
Conclusion & alert: CVE-2024-6893 is rated High Exploit Risk (79/100): CVSS High severity, with high exploitation likelihood (EPSS 91.39%, 100th percentile).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2024-6893
Exploit prediction scoring system (EPSS) score for CVE-2024-6893
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).