Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rfq3-wpjh-ppvg

Опубликовано: 22 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

WSO2 Registry Stored Cross Site Scripting (XSS) vulnerability

WSO2 Registry has been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.

Пакеты

Наименование

org.wso2.carbon.registry:carbon-registry

maven
Затронутые версииВерсия исправления

< 4.7.37

4.7.37

EPSS

Процентиль: 57%
0.00347
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
около 2 лет назад

Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.

EPSS

Процентиль: 57%
0.00347
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79