Show filters
67 Total Results
Displaying 51-60 of 67
Sort by:
Attacker Value
Unknown

CVE-2019-6514

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be stored in the database and then displayed and executed on the same page, aka XSS.
0
Attacker Value
Unknown

CVE-2019-6512

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to enumerate files because of the existence of the file:// wrapper.
0
Attacker Value
Unknown

CVE-2019-6515

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.6.0. Uploaded documents for API documentation are available to an unauthenticated user.
0
Attacker Value
Unknown

CVE-2019-6516

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port-scanning) and to perform requests to adjacent workstations (network-scanning), aka SSRF.
0
Attacker Value
Unknown

CVE-2019-20443

Disclosure Date: May 08, 2019 (last updated February 21, 2025)
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI.
Attacker Value
Unknown

CVE-2019-20439

Disclosure Date: May 08, 2019 (last updated February 21, 2025)
An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in defining a scope in the "manage the API" page of the API Publisher.
Attacker Value
Unknown

CVE-2018-20737

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.
0
Attacker Value
Unknown

CVE-2018-20736

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.
0
Attacker Value
Unknown

CVE-2018-8716

Disclosure Date: April 25, 2018 (last updated November 26, 2024)
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
0
Attacker Value
Unknown

CVE-2017-14995

Disclosure Date: October 04, 2017 (last updated November 26, 2024)
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.
0