ZeroHour

CVE-2017-14651

PoC ×2
CVSS 3.1
4.8 medium
EPSS
4%p90
Published
()
Modified
Description

WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.

Vendors
wso2
Products
api manager, app manager, application server, business process server, business rules server, complex event processor, dashboard server, data analytics server, data services server, enterprise integrator, enterprise mobility manager, governance registry
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.