VulnerabilityModified
CVE-2020-17453
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
MEDIUM 6.1EPSS 26.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 26.22% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wso2/api manager · wso2/api manager analytics · wso2/api microgateway · wso2/enterprise integrator · wso2/identity server · wso2/identity server analytics · wso2/identity server as key manager · wso2/micro integrator
- Source
- cve@mitre.org
References
- https://github.com/JHHAX/CVE-2020-17453-PoCExploit, Third Party Advisory
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1132/
- https://twitter.com/JacksonHHax/status/1374681422678519813Exploit, Third Party Advisory
- https://github.com/JHHAX/CVE-2020-17453-PoCExploit, Third Party Advisory
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1132/
- https://twitter.com/JacksonHHax/status/1374681422678519813Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.