SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-20443

A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI.

MEDIUM 4.8EPSS 0.80%

Does this matter?

Lower severity and a low EPSS score (0.80%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI.

CVSS 3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS
0.80% probability · 55th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
wso2/api manager · wso2/enterprise integrator · wso2/identity server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.