CVE-2020-17453
05.04.2021, 22:15
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
Vendor | Product | Version |
---|---|---|
wso2 | api_manager | 𝑥 ≤ 3.2.0 |
wso2 | api_manager_analytics | 2.2.0 |
wso2 | api_manager_analytics | 2.5.0 |
wso2 | api_manager_analytics | 2.6.0 |
wso2 | api_microgateway | 2.2.0 |
wso2 | enterprise_integrator | 𝑥 ≤ 6.6.0 |
wso2 | identity_server | 𝑥 ≤ 5.10.0 |
wso2 | identity_server_analytics | 5.4.0 |
wso2 | identity_server_analytics | 5.4.1 |
wso2 | identity_server_analytics | 5.5.0 |
wso2 | identity_server_analytics | 5.6.0 |
wso2 | identity_server_as_key_manager | 5.5.0 |
wso2 | identity_server_as_key_manager | 5.6.0 |
wso2 | identity_server_as_key_manager | 5.7.0 |
wso2 | identity_server_as_key_manager | 5.9.0 |
wso2 | identity_server_as_key_manager | 5.10.0 |
wso2 | micro_integrator | 1.0.0 |
𝑥
= Vulnerable software versions
References