Stored XSS Vulnerability in WSO2 Application and Business Process Servers
CVE-2017-14995

6.1MEDIUM

Key Information:

Vendor

Wso2

Vendor
CVE Published:
4 October 2017

What is CVE-2017-14995?

The Management Console across various WSO2 products is susceptible to a stored Cross-Site Scripting (XSS) vulnerability. This security issue arises when malicious scripts are stored and executed on the client side, posing risks to data integrity and user security. Attackers can exploit this vulnerability to inject harmful scripts into the applications, which may lead to unauthorized data access or manipulation. It is critical for users of the affected versions to apply the necessary security patches to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.