CVE-2019-15108: XSS
An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filename to the file-upload feature of the event simulator component.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-15108?
CVE-2019-15108 is a vulnerability discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457 that allows cross-site scripting (XSS) attacks via a crafted filename to the file-upload feature of the event simulator component.
How does CVE-2019-15108 affect WSO2 API Manager?
CVE-2019-15108 affects WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457.
What is the severity of CVE-2019-15108?
CVE-2019-15108 has a severity rating of medium with a CVSS score of 4.8.
How can I fix CVE-2019-15108 in WSO2 API Manager?
To fix CVE-2019-15108 in WSO2 API Manager, update to version WSO2-CARBON-PATCH-4.4.0-4457 or later.
Where can I find more information about CVE-2019-15108?
More information about CVE-2019-15108 can be found in the WSO2 security advisory WSO2-2019-0597.