Skip to content

Latest commit

 

History

History
22 lines (12 loc) · 747 Bytes

README.md

File metadata and controls

22 lines (12 loc) · 747 Bytes

WSO2-2021-1261: Multiple Cross-Site Scripting in WSO2 ESB

Due to improper output encoding, multiple Cross Site Scripting (XSS) attacks have been identified in WSO2 ESB.

Vendor Disclosure:

The vendor's disclosure and fix for this vulnerability can be found here.

Why no CVE?

Neither me nor the vendor requested a CVE for this vulnerability.

Requirements:

This vulnerability requires:

  • Some XSSs require valid user credentials

Proof Of Concept:

More details and the exploitation process can be found in this PDF.