Description
An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager 2.2.0, API Manager Analytics 2.2.0, API Microgateway 2.2.0, Data Analytics Server 3.2.0, Enterprise Integrator through 6.6.0, IS as Key Manager 5.5.0, Identity Server 5.5.0 and 5.8.0, Identity Server Analytics 5.5.0, and IoT Server 3.3.0 and 3.3.1.
Remediation
References
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2020/WSO2-2020-0685/
Related Vulnerabilities
CVE-2021-41184 Vulnerability in maven package org.webjars.bower:jquery-ui
CVE-2019-14653 Vulnerability in maven package org.webjars.bower:editor.md
CVE-2023-35157 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2018-8031 Vulnerability in maven package org.apache.tomee:tomee-webapp
CVE-2017-16881 Vulnerability in maven package org.b3log:symphony