CVE-2020-24589
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
Date published : 2020-08-21
https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0742