CVE-2018-20736: XSS
Published Mar 18, 2019
·Updated
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.
Affected Software
1 affected component
WSO2 API Manager=2.6.0
Remediation
Patch Available
Patch Available
Event History
Mar 18, 2019
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
Description
Frequently Asked Questions
1
What is CVE-2018-20736?
CVE-2018-20736 is a vulnerability discovered in WSO2 API Manager 2.1.0 and 2.6.0, which allows for DOM-based XSS attacks in the store section of the product.
2
What is the severity of CVE-2018-20736?
The severity of CVE-2018-20736 is medium with a CVSS score of 5.4.
3
How does CVE-2018-20736 affect WSO2 API Manager?
CVE-2018-20736 affects WSO2 API Manager versions 2.1.0 and 2.6.0.
4
How can I fix CVE-2018-20736?
To fix CVE-2018-20736, it is recommended to apply the security patch released by WSO2.
5
Where can I find more information about CVE-2018-20736?
You can find more information about CVE-2018-20736 in the following references: [link1], [link2], [link3].