CVE-2023-6911
 
Severity Score
4.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
Se han identificado varios productos WSO2 como vulnerables debido a una codificación de salida incorrecta; un atacante puede llevar a cabo un ataque de Cross-Site Scripting (XSS) Almacenado inyectando un payload malicioso en la función de registro de Management Console.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-12-18 CVE Reserved
- 2023-12-18 CVE Published
- 2023-12-23 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
- CAPEC-592: Stored XSS
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wso2 Search vendor "Wso2" | Api Manager Search vendor "Wso2" for product "Api Manager" | 2.2.0 Search vendor "Wso2" for product "Api Manager" and version "2.2.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Api Manager Search vendor "Wso2" for product "Api Manager" | 2.5.0 Search vendor "Wso2" for product "Api Manager" and version "2.5.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Api Manager Search vendor "Wso2" for product "Api Manager" | 2.6.0 Search vendor "Wso2" for product "Api Manager" and version "2.6.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Api Manager Search vendor "Wso2" for product "Api Manager" | 3.0.0 Search vendor "Wso2" for product "Api Manager" and version "3.0.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Api Manager Search vendor "Wso2" for product "Api Manager" | 3.1.0 Search vendor "Wso2" for product "Api Manager" and version "3.1.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Api Manager Search vendor "Wso2" for product "Api Manager" | 3.2.0 Search vendor "Wso2" for product "Api Manager" and version "3.2.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Api Manager Analytics Search vendor "Wso2" for product "Api Manager Analytics" | 2.2.0 Search vendor "Wso2" for product "Api Manager Analytics" and version "2.2.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Api Manager Analytics Search vendor "Wso2" for product "Api Manager Analytics" | 2.5.0 Search vendor "Wso2" for product "Api Manager Analytics" and version "2.5.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Api Microgateway Search vendor "Wso2" for product "Api Microgateway" | 2.2.0 Search vendor "Wso2" for product "Api Microgateway" and version "2.2.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Data Analytics Server Search vendor "Wso2" for product "Data Analytics Server" | 3.2.0 Search vendor "Wso2" for product "Data Analytics Server" and version "3.2.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Enterprise Integrator Search vendor "Wso2" for product "Enterprise Integrator" | 6.1.0 Search vendor "Wso2" for product "Enterprise Integrator" and version "6.1.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Enterprise Integrator Search vendor "Wso2" for product "Enterprise Integrator" | 6.1.1 Search vendor "Wso2" for product "Enterprise Integrator" and version "6.1.1" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Enterprise Integrator Search vendor "Wso2" for product "Enterprise Integrator" | 6.2.0 Search vendor "Wso2" for product "Enterprise Integrator" and version "6.2.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Enterprise Integrator Search vendor "Wso2" for product "Enterprise Integrator" | 6.3.0 Search vendor "Wso2" for product "Enterprise Integrator" and version "6.3.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Enterprise Integrator Search vendor "Wso2" for product "Enterprise Integrator" | 6.4.0 Search vendor "Wso2" for product "Enterprise Integrator" and version "6.4.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Enterprise Integrator Search vendor "Wso2" for product "Enterprise Integrator" | 6.5.0 Search vendor "Wso2" for product "Enterprise Integrator" and version "6.5.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Enterprise Integrator Search vendor "Wso2" for product "Enterprise Integrator" | 6.6.0 Search vendor "Wso2" for product "Enterprise Integrator" and version "6.6.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server As Key Manager Search vendor "Wso2" for product "Identity Server As Key Manager" | 5.5.0 Search vendor "Wso2" for product "Identity Server As Key Manager" and version "5.5.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server As Key Manager Search vendor "Wso2" for product "Identity Server As Key Manager" | 5.6.0 Search vendor "Wso2" for product "Identity Server As Key Manager" and version "5.6.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server As Key Manager Search vendor "Wso2" for product "Identity Server As Key Manager" | 5.7.0 Search vendor "Wso2" for product "Identity Server As Key Manager" and version "5.7.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server As Key Manager Search vendor "Wso2" for product "Identity Server As Key Manager" | 5.9.0 Search vendor "Wso2" for product "Identity Server As Key Manager" and version "5.9.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server As Key Manager Search vendor "Wso2" for product "Identity Server As Key Manager" | 5.10.0 Search vendor "Wso2" for product "Identity Server As Key Manager" and version "5.10.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Search vendor "Wso2" for product "Identity Server" | 5.4.0 Search vendor "Wso2" for product "Identity Server" and version "5.4.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Search vendor "Wso2" for product "Identity Server" | 5.4.1 Search vendor "Wso2" for product "Identity Server" and version "5.4.1" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Search vendor "Wso2" for product "Identity Server" | 5.5.0 Search vendor "Wso2" for product "Identity Server" and version "5.5.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Search vendor "Wso2" for product "Identity Server" | 5.6.0 Search vendor "Wso2" for product "Identity Server" and version "5.6.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Search vendor "Wso2" for product "Identity Server" | 5.7.0 Search vendor "Wso2" for product "Identity Server" and version "5.7.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Search vendor "Wso2" for product "Identity Server" | 5.8.0 Search vendor "Wso2" for product "Identity Server" and version "5.8.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Search vendor "Wso2" for product "Identity Server" | 5.9.0 Search vendor "Wso2" for product "Identity Server" and version "5.9.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Search vendor "Wso2" for product "Identity Server" | 5.10.0 Search vendor "Wso2" for product "Identity Server" and version "5.10.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Analytics Search vendor "Wso2" for product "Identity Server Analytics" | 5.4.0 Search vendor "Wso2" for product "Identity Server Analytics" and version "5.4.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Analytics Search vendor "Wso2" for product "Identity Server Analytics" | 5.4.1 Search vendor "Wso2" for product "Identity Server Analytics" and version "5.4.1" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Analytics Search vendor "Wso2" for product "Identity Server Analytics" | 5.5.0 Search vendor "Wso2" for product "Identity Server Analytics" and version "5.5.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Identity Server Analytics Search vendor "Wso2" for product "Identity Server Analytics" | 5.6.0 Search vendor "Wso2" for product "Identity Server Analytics" and version "5.6.0" | - |
Affected
| ||||||
Wso2 Search vendor "Wso2" | Message Broker Search vendor "Wso2" for product "Message Broker" | 3.2.0 Search vendor "Wso2" for product "Message Broker" and version "3.2.0" | - |
Affected
|