Description
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
Remediation
References
Related Vulnerabilities
WordPress Plugin Side Menu Lite-add sticky fixed buttons SQL Injection (2.2.5)
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9511)
WeBid Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3815)
Ruby on Rails Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-8167)