CVE-2019-20435 describes a reflected Cross-Site Scripting (XSS) vulnerability in WSO2 API Manager version 2.6.0. An attacker could exploit this by manipulating the 'docName' parameter in an HTTP GET request to the inline API documentation editor page within the API Publisher. Rated as MEDIUM severity (CVSS 4.8), this attack requires high privileges and user interaction, with potential impacts including limited confidentiality and integrity compromise. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:2.6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.