Description
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1948001
Related Vulnerabilities
CVE-2023-37478 Vulnerability in npm package @pnpm/exe
CVE-2018-25031 Vulnerability in npm package swagger-ui
CVE-2022-45379 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2020-24922 Vulnerability in maven package com.xuxueli:xxl-job-admin
CVE-2023-48967 Vulnerability in maven package org.noear:solon.serialization.fury