384
VMScore

CVE-2020-17453

Published: 05/04/2021 Updated: 11/01/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

WSO2 Management Console up to and including 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wso2 identity server as key manager 5.7.0

wso2 enterprise integrator

wso2 api microgateway 2.2.0

wso2 identity server

wso2 api manager analytics 2.2.0

wso2 api manager analytics 2.5.0

wso2 identity server analytics 5.5.0

wso2 identity server as key manager 5.5.0

wso2 micro integrator 1.0.0

wso2 identity server analytics 5.4.1

wso2 identity server analytics 5.6.0

wso2 identity server analytics 5.4.0

wso2 identity server as key manager 5.6.0

wso2 identity server as key manager 5.9.0

wso2 identity server as key manager 5.10.0

wso2 api manager analytics 2.6.0

wso2 api manager

Github Repositories

PoC (Proof of Concept) - CVE-2020-17453

CVE-2020-17453 WSO2 Management Console through 510 allows XSS via the carbon/admin/loginjsp msgId parameter PoC (Proof of Concept) <company>com/carbon/admin/loginjsp?msgId=%27;alert(1)// Discoverers Name: Jackson Henry Twitter: @JacksonHHax Name: Nicholas Young

CVE-2020-17453 is a powerful scanner for bug bounty hunters and penetration testers to discover vulnerabilities in their web applications.

Badges License MIT Installation Install CVE-2020-17453 with npm npm install cve-2020-17453 -g Usage Example for single url CVE-2020-17453 -u examplecom Usage Example for list of urls CVE-2020-17453 -l urlstxt -o outtxt Screenshots Help menu Get