An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing the extension to an allowed one.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.excellium-services.com/cert-xlm-advisory | third party advisory |
https://www.excellium-services.com/cert-xlm-advisory/cve-2019-6513/ | third party advisory |