WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
References
| Link | Resource |
|---|---|
| https://github.com/cybersecurityworks/Disclosed/issues/15 | Exploit Technical Description Third Party Advisory |
| https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0265 | Patch Vendor Advisory |
| https://cybersecurityworks.com/zerodays/cve-2017-14651-wso2.html | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-09-21 18:29
Updated : 2020-11-09 17:54
NVD link : CVE-2017-14651
Mitre link : CVE-2017-14651
JSON object : View
Products Affected
wso2
- api_manager
- business_rules_server
- enterprise_mobility_manager
- business_process_server
- application_server
- dashboard_server
- governance_registry
- data_analytics_server
- enterprise_integrator
- message_broker
- data_services_server
- storage_server
- app_manager
- complex_event_processor
- identity_server
- machine_learner
- iot_server
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
