Description
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
Remediation
References
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1225/
Related Vulnerabilities
CVE-2020-25633 Vulnerability in maven package org.jboss.resteasy:resteasy-client-microprofile
CVE-2018-1274 Vulnerability in maven package org.springframework.data:spring-data-commons
CVE-2023-36468 Vulnerability in maven package org.xwiki.platform:xwiki-platform-core
CVE-2018-15756 Vulnerability in maven package org.springframework:spring-web
CVE-2021-34435 Vulnerability in npm package @theia/mini-browser