Vulnerability Details CVE-2019-20442
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.0%
CVSS Severity
CVSS v3 Score 3.5
CVSS v2 Score 3.5
Products affected by CVE-2019-20442
-
cpe:2.3:a:wso2:api_manager:2.6.0
-
cpe:2.3:a:wso2:enterprise_integrator:6.5.0
-
cpe:2.3:a:wso2:identity_server:5.7.0
-
cpe:2.3:a:wso2:identity_server:5.8.0