CVE-2019-20435: XSS
An issue was discovered in WSO2 API Manager 2.6.0. A reflected XSS attack could be performed in the inline API documentation editor page of the API Publisher by sending an HTTP GET request with a harmful docName request parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20435?
CVE-2019-20435 is a vulnerability discovered in WSO2 API Manager 2.6.0 that allows for a reflected XSS attack.
How can CVE-2019-20435 be exploited?
CVE-2019-20435 can be exploited by sending an HTTP GET request with a harmful 'docName' request parameter in the inline API documentation editor page of the API Publisher.
What is the severity of CVE-2019-20435?
CVE-2019-20435 has a severity rating of medium with a CVSS score of 4.8.
How can I fix CVE-2019-20435 in WSO2 API Manager 2.6.0?
To fix CVE-2019-20435 in WSO2 API Manager 2.6.0, apply the necessary patches and updates provided by WSO2 and follow their security advisory.
What is CWE-79?
CWE-79 is a common vulnerability and exposure (CVE) classification for Cross-Site Scripting (XSS) vulnerabilities.