Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvp5-w7h8-5v6c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

An issue was discovered in WSO2 API Manager 2.6.0. A reflected XSS attack could be performed in the inline API documentation editor page of the API Publisher by sending an HTTP GET request with a harmful docName request parameter.

An issue was discovered in WSO2 API Manager 2.6.0. A reflected XSS attack could be performed in the inline API documentation editor page of the API Publisher by sending an HTTP GET request with a harmful docName request parameter.

EPSS

Процентиль: 62%
0.00427
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
около 6 лет назад

An issue was discovered in WSO2 API Manager 2.6.0. A reflected XSS attack could be performed in the inline API documentation editor page of the API Publisher by sending an HTTP GET request with a harmful docName request parameter.

EPSS

Процентиль: 62%
0.00427
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79