Логотип exploitDog
bind:CVE-2024-8008
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-8008

Количество 2

Количество 2

nvd логотип

CVE-2024-8008

8 месяцев назад

A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store connection validation request. A malicious actor can inject a specially crafted payload into the request, causing the browser to execute arbitrary JavaScript in the context of the vulnerable page. This vulnerability may allow UI manipulation, redirection to malicious websites, or data exfiltration from the browser. However, since all session-related sensitive cookies are protected with the httpOnly flag, session hijacking is not possible.

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-xpxp-r8hf-wgf6

8 месяцев назад

WSO2 products vulnerable to Cross-site Scripting

CVSS3: 5.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-8008

A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store connection validation request. A malicious actor can inject a specially crafted payload into the request, causing the browser to execute arbitrary JavaScript in the context of the vulnerable page. This vulnerability may allow UI manipulation, redirection to malicious websites, or data exfiltration from the browser. However, since all session-related sensitive cookies are protected with the httpOnly flag, session hijacking is not possible.

CVSS3: 5.2
0%
Низкий
8 месяцев назад
github логотип
GHSA-xpxp-r8hf-wgf6

WSO2 products vulnerable to Cross-site Scripting

CVSS3: 5.2
0%
Низкий
8 месяцев назад

Уязвимостей на страницу