CVE-2023-31664

A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tenantDomain parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:02

Type Values Removed Values Added
References () https://github.com/adilkhan7/CVE-2023-31664 - Exploit, Third Party Advisory () https://github.com/adilkhan7/CVE-2023-31664 - Exploit, Third Party Advisory
References () https://github.com/wso2/api-manager/issues?q=is%3Aissue+is%3Aclosed+label%3AComponent%2FAPIM+closed%3A2022-04-05..2023-03-11 - Issue Tracking () https://github.com/wso2/api-manager/issues?q=is%3Aissue+is%3Aclosed+label%3AComponent%2FAPIM+closed%3A2022-04-05..2023-03-11 - Issue Tracking
References () https://github.com/wso2/product-apim/releases/tag/v4.2.0 - Release Notes () https://github.com/wso2/product-apim/releases/tag/v4.2.0 - Release Notes

30 May 2023, 18:46

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79
First Time Wso2
Wso2 api Manager
CPE cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
References (CONFIRM) https://github.com/wso2/api-manager/issues?q=is%3Aissue+is%3Aclosed+label%3AComponent%2FAPIM+closed%3A2022-04-05..2023-03-11 - (CONFIRM) https://github.com/wso2/api-manager/issues?q=is%3Aissue+is%3Aclosed+label%3AComponent%2FAPIM+closed%3A2022-04-05..2023-03-11 - Issue Tracking
References (MISC) https://github.com/adilkhan7/CVE-2023-31664 - (MISC) https://github.com/adilkhan7/CVE-2023-31664 - Exploit, Third Party Advisory
References (CONFIRM) https://github.com/wso2/product-apim/releases/tag/v4.2.0 - (CONFIRM) https://github.com/wso2/product-apim/releases/tag/v4.2.0 - Release Notes

Information

Published : 2023-05-23 01:15

Updated : 2024-11-21 08:02


NVD link : CVE-2023-31664

Mitre link : CVE-2023-31664

CVE.ORG link : CVE-2023-31664


JSON object : View

Products Affected

wso2

  • api_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')