Description
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Policy Administration user interface.
Remediation
References
https://cybersecurityworks.com/zerodays/cve-2020-14444-wso2.html
https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0707
Related Vulnerabilities
CVE-2021-21430 Vulnerability in maven package org.openapitools:openapi-generator-project
CVE-2017-16144 Vulnerability in npm package myserver.alexcthomas18
CVE-2019-18213 Vulnerability in maven package org.lsp4xml:org.eclipse.lsp4xml.extensions.web
CVE-2021-23431 Vulnerability in npm package joplin
CVE-2024-36401 Vulnerability in maven package org.geoserver.web:gs-web-app