3.5
CVSSv2

CVE-2019-20443

Published: 28/01/2020 Updated: 10/11/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

An issue exists in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wso2 api manager 2.6.0

wso2 enterprise integrator 6.5.0

wso2 identity server 5.7.0

wso2 identity server 5.8.0

Github Repositories

Security advisories discovered by CSW Researchers

Security-Advisories Below are advisories for security vulnerabilities in third-party products discovered by CSW Researchers Publised Date Severity CVE Title January 27, 2020 Medium CVE-2019-20443 Cross-Site Scripting (XSS) vulnerability Contact CSW is always open to feedback and suggestions If you would like to talk to us, please feel free to email us at disclose@cyb