Description
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
Remediation
References
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1225/
Related Vulnerabilities
CVE-2021-31812 Vulnerability in maven package org.apache.pdfbox:pdfbox
CVE-2017-16153 Vulnerability in npm package gaoxuyan
CVE-2020-11991 Vulnerability in maven package org.apache.cocoon:cocoon-core
CVE-2019-17195 Vulnerability in maven package com.nimbusds:nimbus-jose-jwt
CVE-2020-13943 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core