An issue exists in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing the extension to an allowed one.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
wso2 api manager 2.6.0 |