CVE-2019-6513

MEDIUM

Wso2 API Manager - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing the extension to an allowed one.

Scores

CVSS v3 5.4
EPSS 0.0029
EPSS Percentile 52.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Details

CWE
CWE-434
Status published
Products (1)
wso2/api_manager 2.6.0
Published May 21, 2019
Tracked Since Feb 18, 2026