Loading HuntDB...

GHSA-mfgw-52pj-hrhg

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. This affects WSO2 API Manager 2.2.0 and above through 4.0.0; WSO2 Identity Server 5.2.0 and above through 5.11.0; WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, and 5.6.0; WSO2 Identity Server as Key Manager 5.3.0 and above through 5.10.0; and WSO2 Enterprise Integrator 6.2.0 and above through 6.6.0.

Related CVEs

Key Information

GHSA ID
GHSA-mfgw-52pj-hrhg
Published
April 20, 2022 12:00 AM
Last Modified
July 2, 2024 9:32 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.