Reflected Cross-Site Scripting in WSO2 API Manager by WSO2
CVE-2020-17454

6.1MEDIUM

Key Information:

Vendor

Wso2

Vendor
CVE Published:
21 October 2020

What is CVE-2020-17454?

WSO2 API Manager versions 3.1.0 and earlier are susceptible to reflected cross-site scripting (XSS) vulnerabilities within the admin interface's publisher component. Attackers can exploit this flaw by injecting malicious scripts into the owner POST parameter, as user input is not adequately filtered. This results in an error modal displaying the injected payload, potentially leading to unauthorized script execution. Furthermore, the vulnerability can be additionally exploited through cross-site request forgery (CSRF), amplifying the risk of this security issue.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.