ZeroHour

CVE-2023-6911

CVSS 3.1
4.8 medium
EPSS
<1%p34
Published
()
Modified
Description

Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.

Vendors
wso2
Products
api manager, api manager analytics, api microgateway, data analytics server, enterprise integrator, identity server as key manager, identity server, identity server analytics, message broker
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.