CVE-2024-6893 is a high-severity XML External Entity (XXE) injection vulnerability affecting Journyx Journyx products, specifically within the "soap_cgi.pyc" API handler. This flaw allows unauthenticated attackers to read local files, perform Server-Side Request Forgery (SSRF), and potentially cause denial of service by overwhelming web server resources. With a CVSS score of 7.5 (HIGH) and an EPSS score indicating high exploitability, the vulnerability is easily exploitable over the network without user interaction. While there is no evidence of active exploitation or public exploit code on Metasploit or ExploitDB, a Nuclei template exists, and the lack of community discussion or media coverage is typical for most CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.5.4CPE matchmatch criteria | cpe:2.3:a:journyx:journyx:11.5.4:*:*:*:*:linux:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.