Reflected XSS in WSO2 Enterprise Integrator Management Console
CVE-2019-19587

6.1MEDIUM

Key Information:

Vendor

Wso2

Vendor
CVE Published:
5 December 2019

What is CVE-2019-19587?

A reflected cross-site scripting vulnerability exists in WSO2 Enterprise Integrator version 6.5.0. This issue arises when the message processor configuration is updated through the source view in the Management Console. Attackers can exploit this vulnerability by crafting a malicious URL that targets the affected component. When unsuspecting users access this URL, the injected malicious script can execute in their browser, potentially leading to unauthorized actions or information disclosure.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.