CVE-2024-6893: Journyx
High severity, CVSS 7.5. EPSS: 32.9% chance of exploitation in the next 30 days.
The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.
Affected products
- Journyx Journyx: version 11.5.4 only
Published 2024-08-08. Last modified 2026-06-17.