Session Hijacking Vulnerability in WSO2 API Manager and Other Products
CVE-2020-24703
8.8HIGH
What is CVE-2020-24703?
An issue was discovered in certain WSO2 products, where a valid Carbon Management Console session cookie may be inadvertently transmitted to an attacker-controlled server. This occurs when a victim submits a crafted 'Try It' request, allowing an attacker to hijack the session. The vulnerability impacts several WSO2 products, potentially exposing sensitive information and compromising the integrity of user sessions.