Show filters
64 Total Results
Displaying 41-50 of 64
Sort by:
Attacker Value
Unknown

CVE-2019-20442

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI.
Attacker Value
Unknown

CVE-2019-20440

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the update API documentation feature of the API Publisher.
Attacker Value
Unknown

CVE-2019-19587

Disclosure Date: December 05, 2019 (last updated November 27, 2024)
In WSO2 Enterprise Integrator 6.5.0, reflected XSS occurs when updating the message processor configuration from the source view in the Management Console.
Attacker Value
Unknown

CVE-2019-18881

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile.
Attacker Value
Unknown

CVE-2019-18882

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled.
Attacker Value
Unknown

CVE-2019-15108

Disclosure Date: August 16, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filename to the file-upload feature of the event simulator component.
Attacker Value
Unknown

CVE-2019-6513

Disclosure Date: May 21, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing the extension to an allowed one.
0
Attacker Value
Unknown

CVE-2019-6514

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be stored in the database and then displayed and executed on the same page, aka XSS.
0
Attacker Value
Unknown

CVE-2019-6512

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to enumerate files because of the existence of the file:// wrapper.
0
Attacker Value
Unknown

CVE-2019-6515

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.6.0. Uploaded documents for API documentation are available to an unauthenticated user.
0