Cross-Site Scripting Vulnerabilities in WSO2 Carbon from WSO2
CVE-2016-4316

6.1MEDIUM

Key Information:

Vendor

Wso2

Status
Vendor
CVE Published:
17 February 2017

What is CVE-2016-4316?

Multiple cross-site scripting (XSS) vulnerabilities exist in WSO2 Carbon 4.4.5, enabling remote attackers to inject arbitrary web scripts or HTML. The vulnerable parameters include 'setName' in identity-mgt/challenges-mgt.jsp, 'webappType' and 'httpPort' in webapp-list/webapp_info.jsp, 'dsName' and 'description' in ndatasource/newdatasource.jsp, 'phase' in viewflows/handlers.jsp, and 'url' in ndatasource/validateconnection-ajaxprocessor.jsp. Successful exploitation could allow attackers to manipulate the web application's behavior, potentially leading to cookie theft and session hijacking.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.