WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
References
Link | Resource |
---|---|
https://github.com/cybersecurityworks/Disclosed/issues/15 | Exploit Technical Description Third Party Advisory |
https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0265 | Patch Vendor Advisory |
https://cybersecurityworks.com/zerodays/cve-2017-14651-wso2.html | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-09-21 11:29
Updated : 2020-11-09 09:54
NVD link : CVE-2017-14651
Mitre link : CVE-2017-14651
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
wso2
- enterprise_mobility_manager
- business_rules_server
- application_server
- message_broker
- api_manager
- iot_server
- app_manager
- data_analytics_server
- data_services_server
- governance_registry
- machine_learner
- dashboard_server
- business_process_server
- identity_server
- complex_event_processor
- enterprise_integrator
- storage_server