Showing 2 vulnerabilities on this page for api_manager

Signals CISA KEV Ransomware Nuclei
WSO2 vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WSO2 api_manager Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.

CWE-79Apr 5, 20211 related artifact
CVSS6.1v3.1EPSS26.1%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WSO2 api_manager Improper Restriction of XML External Entity Reference

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.

CWE-611CWE-776Aug 21, 20201 related artifact
CVSS9.1v3.1EPSS26.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX