Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wso2 identity server 5.3.0 vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/ser...
Wso2 Identity Server Analytics 5.5.0
Wso2 Identity Server Analytics 5.4.1
Wso2 Identity Server Analytics 5.6.0
Wso2 Identity Server Analytics 5.4.0
Wso2 Api Manager
Wso2 Identity Server
Wso2 Enterprise Integrator
Wso2 Identity Server As Key Manager
31 Github repositories
4.3
CVSSv2
CVE-2021-36760
In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter. Once the username or password reset procedure is completed, the J...
Wso2 Api Manager 3.0.0
Wso2 Api Manager 3.1.0
Wso2 Api Manager 3.2.0
Wso2 Api Manager 4.0.0
Wso2 Identity Server 5.7.0
Wso2 Identity Server 5.8.0
Wso2 Identity Server 5.9.0
Wso2 Identity Server 5.10.0
Wso2 Identity Server 5.11.0
Wso2 Identity Server As Key Manager 5.3.0
Wso2 Identity Server As Key Manager 5.5.0
Wso2 Identity Server As Key Manager 5.6.0
Wso2 Identity Server As Key Manager 5.7.0
Wso2 Identity Server As Key Manager 5.9.0
Wso2 Identity Server As Key Manager 5.10.0
Wso2 Iot Server 3.3.1
3.5
CVSSv2
CVE-2018-8716
WSO2 Identity Server prior to 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
Wso2 Identity Server
1 EDB exploit
3.5
CVSSv2
CVE-2017-14651
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
Wso2 Enterprise Mobility Manager 2.2.0
Wso2 Data Services Server 3.5.1
Wso2 Api Manager 2.1.0
Wso2 Message Broker 3.2.0
Wso2 Machine Learner 1.2.0
Wso2 Iot Server 3.0.0
Wso2 Identity Server 5.3.0
Wso2 Complex Event Processor 4.2.0
Wso2 Business Rules Server 2.2.0
Wso2 Business Process Server 3.6.0
Wso2 Application Server 5.3.0
Wso2 Storage Server 1.5.0
Wso2 Governance Registry 5.4.0
Wso2 Enterprise Integrator 6.1.1
Wso2 Dashboard Server 2.0.0
Wso2 App Manager 1.2.0
Wso2 Data Analytics Server 3.1.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started