← Back to browse · API

CVE-2024-6893

Severity
HIGH
CVSS
7.5
EPSS
0.32916
Risk score
41.52
CISA KEV
No
PoC
No
Published
2024-08-07
Modified
2024-08-08
First seen
2026-08-07
Aliases
EUVD-2024-47882, GHSA-9HXQ-VV35-9R5R
Products
Journyx:Journyx (jtime) 11.5.4
Sources
euvd EUVD-2024-47882

Description

The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.

References