CVE-2019-25075: Gravitee API Management
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.
Affected products
- Gravitee API Management: before 1.25.3 (fixed in 1.25.3)
Published 2022-08-23. Last modified 2026-06-17.