WSO2 Management Console Cross-Site Scripting

medium Web App Scanning Plugin ID 114261

Synopsis

WSO2 Management Console Cross-Site Scripting

Description

The management console of multiple WSO2 products suffer from a Cross-Site Scripting vulnerability :
- WSO2 API Manager versions 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, 4.0.0
- WSO2 API Manager Analytics versions 2.2.0, 2.5.0, 2.6.0
- WSO2 API Microgateway version 2.2.0
- WSO2 Data Analytics Server version 3.2.0 - WSO2 Entreprise Integrator versions 6.2.0, 6.3.0, 6.4.0, 6.5.0, 6.6.0
- WSO2 IS as Key Manager versions 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0
- WSO2 Identity Server versions 5.5.0, 5.6.0, 5.7.0, 5.8.0, 5.9.0, 5.10.0, 5.11.0, 6.0.0
- WSO2 Identity Server Analytics versions 5.5.0, 5.6.0

By leveraging this vulnerability, a remote and unauthenticated attacker can target management console users browsers to perform arbitrary operations.

Solution

Apply the fixed update level (or later) according to the WSO2 advisory.

See Also

https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2022/WSO2-2021-1603/

Plugin Details

Severity: Medium

ID: 114261

Type: remote

Published: 4/22/2024

Updated: 4/22/2024

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 3.8

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2022-29548

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS Score Source: CVE-2022-29548

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/1/2022

Vulnerability Publication Date: 4/1/2022

Reference Information

CVE: CVE-2022-29548