CVE-2023-6911
Published: Dec 18, 2023
Modified: Aug 2, 2024
CVSS v3.1
4.8
Description
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
| Vendor | Product | Versions |
|---|---|---|
WSO2 | WSO2 API Manager | unknown 0 - < 2.2.0.0affected 2.2.0.0 - < 2.2.0.1affected 2.5.0.0 - < 2.5.0.1affected 2.6.0.0 - < 2.6.0.1affected 3.0.0.0 - < 3.0.0.1+2 more versions |
WSO2 | WSO2 API Manager Analytics | unknown 0 - < 2.2.0.0affected 2.2.0.0 - < 2.2.0.1affected 2.5.0.0 - < 2.5.0.1 |
WSO2 | WSO2 API Microgateway | unknown 0 - < 2.2.0.0affected 2.2.0.0 - < 2.2.0.1 |
WSO2 | WSO2 Data Analytics Server | unknown 0 - < 3.2.0.0affected 3.2.0.0 - < 3.2.0.1 |
WSO2 | WSO2 Enterprise Integrator | unknown 0 - < 6.1.0.0affected 6.1.0.0 - < 6.1.0.9affected 6.1.1.0 - < 6.1.1.9affected 6.2.0.0 - < 6.2.0.7affected 6.3.0.0 - < 6.3.0.1+3 more versions |
WSO2 | WSO2 IS as Key Manager | unknown 0 - < 5.5.0.0affected 5.5.0.0 - < 5.5.0.1affected 5.6.0.0 - < 5.6.0.1affected 5.7.0.0 - < 5.7.0.1affected 5.9.0.0 - < 5.9.0.1+1 more versions |
WSO2 | WSO2 Identity Server | unknown 0 - < 5.4.0.0affected 5.4.0.0 - < 5.4.0.4affected 5.4.1.0 - < 5.4.1.3affected 5.5.0.0 - < 5.5.0.1affected 5.6.0.0 - < 5.6.0.1+4 more versions |
WSO2 | WSO2 Identity Server Analytics | unknown 0 - < 5.4.0.0affected 5.4.0.0 - < 5.4.0.2affected 5.4.1.0 - < 5.4.1.2affected 5.5.0.0 - < 5.5.0.1affected 5.6.0.0 - < 5.6.0.1 |
WSO2 | WSO2 Message Broker | unknown 0 - < 3.2.0.0affected 3.2.0.0 - < 3.2.0.3 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now