CVE-2020-27885
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability the attacker can hijack a logged-in user’s session by stealing cookies which means that a malicious hacker can change the logged-in user’s password and invalidate the session of the victim while the hacker maintains access.
Una vulnerabilidad de tipo Cross-Site Scripting (XSS) en WSO2 API Manager versión 3.1.0. Al explotar una vulnerabilidad de tipo Cross-site scripting el atacante puede secuestrar la sesión de un usuario conectado mediante el robo de cookies, lo que significa que un hacker malicioso puede cambiar la contraseña del usuario conectado e invalidar la sesión de la víctima mientras el hacker mantiene el acceso
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-27 CVE Reserved
- 2020-10-29 CVE Published
- 2023-07-15 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.rodrigofavarini.com.br/cybersecurity/multiple-xss-on-api-manager-3-1-0 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.wso2.com/display/Security/2020+Advisories | 2020-11-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wso2 Search vendor "Wso2" | Api Manager Search vendor "Wso2" for product "Api Manager" | 3.1.0 Search vendor "Wso2" for product "Api Manager" and version "3.1.0" | - |
Affected
|