Showing 2 vulnerabilities on this page for WSO2 API Manager Analytics

Signals CISA KEV Ransomware Nuclei
WSO2 vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WSO2 Registry Stored Cross Site Scripting (XSS) vulnerability

Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.

CWE-79Dec 18, 2023
CVSS4.8v3.1EPSS0.406%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

WSO2 products vulnerable to XML External Entity attack

Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.

CWE-611Dec 15, 2023
CVSS4.6v3.1EPSS0.482%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX