WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled.Referenceshttps://docs.wso2.com/display/Security/Security+Advisory+WSO2-2019-0625