CVE-2019-20438: XSS
Published Jan 27, 2020
·Updated
An issue was discovered in WSO2 API Manager 2.6.0. A potential stored Cross-Site Scripting (XSS) vulnerability has been identified in the inline API documentation editor page of the API Publisher.
Affected Software
1 affected component
WSO2 API Manager=2.6.0
Event History
Jan 27, 2020
CVE Published
via MITRE·11:37 PM
Data Sourced
via MITRE·11:37 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-20438.
2
What is the severity of CVE-2019-20438?
The severity of CVE-2019-20438 is medium (4.8).
3
What is the affected software?
The affected software is WSO2 API Manager version 2.6.0.
4
What is the description of this vulnerability?
This vulnerability is a potential stored Cross-Site Scripting (XSS) vulnerability in the inline API documentation editor page of the API Publisher in WSO2 API Manager 2.6.0.
5
How can I fix CVE-2019-20438?
To fix CVE-2019-20438, you should update to the latest version of the WSO2 API Manager.