PT-2020-10453 · Wso2 · Wso2 Enterprise Integrator+3

Sathish Kumar Balakrishnan

·

Published

2020-01-27

·

Updated

2020-11-10

·

CVE-2019-20442

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WSO2 API Manager version 2.6.0 WSO2 Enterprise Integrator version 6.5.0 WSO2 IS as Key Manager version 5.7.0 WSO2 Identity Server version 5.8.0
Description A potential stored Cross-Site Scripting (XSS) vulnerability has been identified in the roleToAuthorize component of the registry UI. This issue affects the specified WSO2 products, potentially allowing for malicious script execution.
Recommendations For WSO2 API Manager version 2.6.0, update to a version that includes a fix for the stored Cross-Site Scripting vulnerability. For WSO2 Enterprise Integrator version 6.5.0, update to a version that includes a fix for the stored Cross-Site Scripting vulnerability. For WSO2 IS as Key Manager version 5.7.0, update to a version that includes a fix for the stored Cross-Site Scripting vulnerability. For WSO2 Identity Server version 5.8.0, update to a version that includes a fix for the stored Cross-Site Scripting vulnerability. As a temporary workaround, consider restricting access to the registry UI to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20442

Affected Products

Wso2 Api Manager
Wso2 Enterprise Integrator
Wso2 Is As Key Manager
Wso2 Identity Server