4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD
Description
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
Affected (17)
Products: Wso2: Api Manager, App Manager, Application Server, Business Process Server, Business Rules Server, Complex Event Processor, Dashboard Server, Data Analytics Server, Data Services Server, Enterprise Integrator, Enterprise Mobility Manager, Governance Registry, Identity Server, Iot Server, Machine Learner, Message Broker, Storage Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.1.0 | |
| Version 1.2.0 | |
| Version 5.3.0 | |
| Version 3.6.0 | |
| Version 2.2.0 | |
| Version 4.2.0 | |
| Version 2.0.0 | |
| Version 3.1.0 | |
| Version 3.5.1 | |
| Version 6.1.1 | |
| Version 2.2.0 | |
| Version 5.4.0 | |
| Version 5.3.0 | |
| Version 3.0.0 | |
| Version 1.2.0 | |
| Version 3.2.0 | |
| Version 1.5.0 |
References (6)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
ExploitTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory
Timeline
No history available yet.