CVE-2019-6513

MEDIUM

WSO2 API Manager 2.6.0 - Authenticated Unrestricted File Upload via API Documentation

Title source: llm
STIX 2.1

Description

An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing the extension to an allowed one.

Scores

CVSS v3 5.4
EPSS 0.0137
EPSS Percentile 68.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Details

CWE
CWE-434
Status published
Products (1)
wso2/api_manager 2.6.0
Published May 21, 2019
Tracked Since Feb 18, 2026