Description
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1948001
Related Vulnerabilities
CVE-2013-4221 Vulnerability in maven package org.restlet:org.restlet
CVE-2023-48309 Vulnerability in npm package next-auth
CVE-2022-4137 Vulnerability in maven package org.keycloak:keycloak-themes
CVE-2015-6748 Vulnerability in maven package org.jsoup:jsoup
CVE-2023-45137 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates