Reflected XSS Vulnerability in WSO2 API Manager 2.6.0 Discovered
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A reflected cross-site scripting (XSS) vulnerability, identified as CVE-2019-20435, was discovered in WSO2 API Manager version 2.6.0. This vulnerability allows attackers to exploit the inline API documentation editor page of the API Publisher by sending a malicious HTTP GET request with a harmful 'docName' parameter. The attack requires only LAN or WiFi adjacency to be successful. The vulnerability has been reproduced in a sandboxed environment, indicating its potential for exploitation. Affected users are advised to download the relevant patch based on their product version. The CVE was published on January 27, 2020, and has been updated in the NVD as of June 9, 2026. Security professionals should prioritize applying the patch to mitigate risks associated with this vulnerability.
Key Points: • CVE-2019-20435 is a reflected XSS vulnerability in WSO2 API Manager 2.6.0. • Attackers can exploit this vulnerability via malicious HTTP GET requests. • Users are urged to apply the relevant patches to protect their systems.