Reflected XSS Vulnerability in WSO2 API Manager 2.6.0 Discovered
Article Content
- •CVE-2019-20435 is a reflected XSS vulnerability in WSO2 API Manager 2.6.0.
- •Attackers can exploit this vulnerability via malicious HTTP GET requests.
- •Users are urged to apply the relevant patches to protect their systems.
A reflected cross-site scripting (XSS) vulnerability, identified as CVE-2019-20435, was discovered in WSO2 API Manager version 2.6.0. This vulnerability allows attackers to exploit the inline API documentation editor page of the API Publisher by sending a malicious HTTP GET request with a harmful 'docName' parameter. The attack requires only LAN or WiFi adjacency to be successful. The vulnerability has been reproduced in a sandboxed environment, indicating its potential for exploitation. Affected users are advised to download the relevant patch based on their product version. The CVE was published on January 27, 2020, and has been updated in the NVD as of June 9, 2026. Security professionals should prioritize applying the patch to mitigate risks associated with this vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track WSO2 and CVE-2019-20435 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…