WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://twitter.com/JacksonHHax/status/1374681422678519813 | third party advisory exploit |
https://github.com/JHHAX/CVE-2020-17453-PoC | third party advisory exploit |
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1132/ |