CVE-2016-4316

MEDIUM

WSO2 Carbon 4.4.5 - Stored Cross-Site Scripting via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-4316. PoCs published by hyp3rlinx.

AI-analyzed exploit summary The exploit demonstrates multiple persistent and reflected XSS vulnerabilities in WSO2 Carbon v4.4.5, allowing attackers to inject malicious scripts to steal session cookies. The PoC includes specific URLs and payloads to trigger the vulnerabilities.

Description

Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the (2) webappType or (3) httpPort parameter to webapp-list/webapp_info.jsp; the (4) dsName or (5) description parameter to ndatasource/newdatasource.jsp; the (6) phase parameter to viewflows/handlers.jsp; or the (7) url parameter to ndatasource/validateconnection-ajaxprocessor.jsp.

Exploits (1)

exploitdb WORKING POC VERIFIED
by hyp3rlinx · textwebappsjsp
https://www.exploit-db.com/exploits/40241

The exploit demonstrates multiple persistent and reflected XSS vulnerabilities in WSO2 Carbon v4.4.5, allowing attackers to inject malicious scripts to steal session cookies. The PoC includes specific URLs and payloads to trigger the vulnerabilities.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: WSO2 Carbon v4.4.5
No auth needed
Prerequisites: Access to the target server's web interface
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/138331/WSO2-Carbon-4.4.5-Cross-Site-Scripting.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92473
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/539201/100/0/threaded
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40241/

Scores

CVSS v3 6.1
EPSS 0.0400
EPSS Percentile 89.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (4)
org.wso2.carbon.commons/org.wso2.carbon.messageflows.ui 0Maven
org.wso2.carbon.commons/org.wso2.carbon.ndatasource.ui 0Maven
org.wso2.carbon.identity.framework/org.wso2.carbon.identity.mgt.ui 0Maven
wso2/carbon 4.4.5
Published Feb 17, 2017
Tracked Since Feb 18, 2026