Record summary

CVE-2017-14651 has a selected CVSS score of 4.8 (medium); EIP currently links 1 Nuclei template.

Description

WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMWSO2 Data Analytics Server 3.1.0 - Cross-Site ScriptingCVSS 4.8

WSO2 Data Analytics Server 3.1.0 is susceptible to cross-site scripting in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Upgrade to a patched version of WSO2 Data Analytics Server or apply the necessary security patches provided by the vendor.

WeaknessesCWE-79
Authorsmass0ma
Template tagscvecve2017wso2xssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:wso2:api_manager:2.1.0:*:*:*:*:*:*:*
Shodan: http.favicon.hash:1398055326
FOFA: icon_hash=1398055326
Google: inurl:"carbon/admin/login"

Source: ProjectDiscovery

References

4