CVE-2025-13590 | WSO2 API Manager unrestricted upload
A vulnerability was found in WSO2 API Manager, API Control Plane, Universal Gateway, Traffic Manager and org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl. It has been classified as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2025-13590. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.