PT-2017-13612 · Wso2 · Wso2 Data Analytics Server

Sathish

·

Published

2017-09-21

·

Updated

2020-11-09

·

CVE-2017-14651

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WSO2 Data Analytics Server version 3.1.0
Description The issue concerns a security problem where an attacker can inject malicious scripts. This is possible through the collectionName or parentPath parameter in the "carbon/resources/add collection ajaxprocessor.jsp" endpoint.
Recommendations For WSO2 Data Analytics Server version 3.1.0, consider restricting access to the "carbon/resources/add collection ajaxprocessor.jsp" endpoint until a patch is available, and avoid using the collectionName or parentPath parameters in this endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14651

Affected Products

Wso2 Data Analytics Server