CVE-2023-6838

Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated and unauthenticated requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:wso2:identity_server_as_key_manager:5.10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*

History

19 Dec 2023, 13:42

Type Values Removed Values Added
CPE cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_as_key_manager:5.10.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*
First Time Wso2 identity Server
Wso2 api Manager
Wso2 identity Server As Key Manager
Wso2
References () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1233/ - () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1233/ - Vendor Advisory

15 Dec 2023, 13:41

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad XSS reflejada se puede explotar alterando un parámetro de solicitud en el endpoint de autenticación. Esto se puede realizar tanto en solicitudes autenticadas como no autenticadas.

15 Dec 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-15 10:15

Updated : 2023-12-19 13:42


NVD link : CVE-2023-6838

Mitre link : CVE-2023-6838

CVE.ORG link : CVE-2023-6838


JSON object : View

Products Affected

wso2

  • identity_server_as_key_manager
  • identity_server
  • api_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')