Description
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
Remediation
References
Related Vulnerabilities
WordPress Plugin Business Hours Pro Arbitrary File Upload (5.5.0)
WordPress Plugin OdiHost Newsletter 'openstat.php' SQL Injection (1.0)
PHP Numeric Errors Vulnerability (CVE-2014-3669)
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.36)
WordPress Plugin WebP Converter for Media Cross-Site Request Forgery (1.0.2)