Описание
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-17453
- https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-1132
- https://github.com/JHHAX/CVE-2020-17453-PoC
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1132
- https://twitter.com/JacksonHHax/status/1374681422678519813
Связанные уязвимости
CVSS3: 6.1
nvd
почти 5 лет назад
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.