Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4x6x-rggp-ff9q

Опубликовано: 05 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.2

Описание

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, a malicious actor can inject arbitrary JavaScript into the response, leading to reflected XSS.

Successful exploitation could result in UI manipulation, redirection to malicious websites, or data theft from the browser. However, session-related sensitive cookies are protected with the httpOnly flag, which mitigates the risk of session hijacking.

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, a malicious actor can inject arbitrary JavaScript into the response, leading to reflected XSS.

Successful exploitation could result in UI manipulation, redirection to malicious websites, or data theft from the browser. However, session-related sensitive cookies are protected with the httpOnly flag, which mitigates the risk of session hijacking.

EPSS

Процентиль: 10%
0.00036
Низкий

5.2 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.2
nvd
3 месяца назад

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, a malicious actor can inject arbitrary JavaScript into the response, leading to reflected XSS. Successful exploitation could result in UI manipulation, redirection to malicious websites, or data theft from the browser. However, session-related sensitive cookies are protected with the httpOnly flag, which mitigates the risk of session hijacking.

EPSS

Процентиль: 10%
0.00036
Низкий

5.2 Medium

CVSS3

Дефекты

CWE-79