CVE-2023-6835
 
Severity Score
5.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating could be manipulated.
Se han identificado varios productos WSO2 como vulnerables debido a la falta de validación de entrada del lado del servidor en la función Foro; la clasificación API podría manipularse.
Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating could be manipulated.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-12-15 CVE Reserved
- 2023-12-15 CVE Published
- 2024-08-02 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
- CAPEC-153: Input Data Manipulation
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wso2 Search vendor "Wso2" | Api Manager Search vendor "Wso2" for product "Api Manager" | 2.2.0 Search vendor "Wso2" for product "Api Manager" and version "2.2.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Api Manager Search vendor "Wso2" for product "Api Manager" | 2.5.0 Search vendor "Wso2" for product "Api Manager" and version "2.5.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Api Manager Search vendor "Wso2" for product "Api Manager" | 2.6.0 Search vendor "Wso2" for product "Api Manager" and version "2.6.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Iot Server Search vendor "Wso2" for product "Iot Server" | 3.3.1 Search vendor "Wso2" for product "Iot Server" and version "3.3.1" | - |
Affected
|