WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
References
Link | Resource |
---|---|
https://cybersecurityworks.com/zerodays/cve-2017-14651-wso2.html | Exploit Third Party Advisory |
https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0265 | Patch Vendor Advisory |
https://github.com/cybersecurityworks/Disclosed/issues/15 | Exploit Technical Description Third Party Advisory |
https://cybersecurityworks.com/zerodays/cve-2017-14651-wso2.html | Exploit Third Party Advisory |
https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0265 | Patch Vendor Advisory |
https://github.com/cybersecurityworks/Disclosed/issues/15 | Exploit Technical Description Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:13
Type | Values Removed | Values Added |
---|---|---|
References | () https://cybersecurityworks.com/zerodays/cve-2017-14651-wso2.html - Exploit, Third Party Advisory | |
References | () https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2017-0265 - Patch, Vendor Advisory | |
References | () https://github.com/cybersecurityworks/Disclosed/issues/15 - Exploit, Technical Description, Third Party Advisory |
Information
Published : 2017-09-21 18:29
Updated : 2024-11-21 03:13
NVD link : CVE-2017-14651
Mitre link : CVE-2017-14651
CVE.ORG link : CVE-2017-14651
JSON object : View
Products Affected
wso2
- iot_server
- api_manager
- application_server
- data_analytics_server
- complex_event_processor
- business_rules_server
- enterprise_integrator
- governance_registry
- data_services_server
- machine_learner
- app_manager
- business_process_server
- dashboard_server
- message_broker
- identity_server
- storage_server
- enterprise_mobility_manager
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')