Show filters
64 Total Results
Displaying 41-50 of 64
Sort by:
Attacker Value
Unknown
CVE-2019-20442
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI.
0
Attacker Value
Unknown
CVE-2019-20440
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the update API documentation feature of the API Publisher.
0
Attacker Value
Unknown
CVE-2019-19587
Disclosure Date: December 05, 2019 (last updated November 27, 2024)
In WSO2 Enterprise Integrator 6.5.0, reflected XSS occurs when updating the message processor configuration from the source view in the Management Console.
0
Attacker Value
Unknown
CVE-2019-18881
Disclosure Date: November 12, 2019 (last updated November 27, 2024)
WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile.
0
Attacker Value
Unknown
CVE-2019-18882
Disclosure Date: November 12, 2019 (last updated November 27, 2024)
WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled.
0
Attacker Value
Unknown
CVE-2019-15108
Disclosure Date: August 16, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filename to the file-upload feature of the event simulator component.
0
Attacker Value
Unknown
CVE-2019-6513
Disclosure Date: May 21, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing the extension to an allowed one.
0
Attacker Value
Unknown
CVE-2019-6514
Disclosure Date: May 14, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be stored in the database and then displayed and executed on the same page, aka XSS.
0
Attacker Value
Unknown
CVE-2019-6512
Disclosure Date: May 14, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to enumerate files because of the existence of the file:// wrapper.
0
Attacker Value
Unknown
CVE-2019-6515
Disclosure Date: May 14, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.6.0. Uploaded documents for API documentation are available to an unauthenticated user.
0