383
VMScore

CVE-2022-29548

Published: 21/04/2022 Updated: 03/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wso2 api manager 2.6.0

wso2 identity server 5.7.0

wso2 identity server as key manager 5.7.0

wso2 enterprise integrator 6.5.0

wso2 api microgateway 2.2.0

wso2 api manager 3.0.0

wso2 enterprise integrator 6.2.0

wso2 enterprise integrator 6.3.0

wso2 api manager analytics 2.2.0

wso2 api manager analytics 2.5.0

wso2 identity server 5.5.0

wso2 identity server analytics 5.5.0

wso2 data analytics server 3.2.0

wso2 identity server as key manager 5.5.0

wso2 api manager 2.2.0

wso2 api manager 3.1.0

wso2 micro integrator 1.0.0

wso2 identity server analytics 5.6.0

wso2 identity server as key manager 5.6.0

wso2 identity server as key manager 5.9.0

wso2 identity server as key manager 5.10.0

wso2 api manager analytics 2.6.0

wso2 identity server 5.11.0

wso2 api manager 4.0.0

wso2 api manager 3.2.0

wso2 identity server 5.9.0

wso2 identity server 5.10.0

wso2 api manager 2.5.0

wso2 enterprise integrator 6.4.0

wso2 enterprise integrator 6.6.0

wso2 identity server 5.6.0

Exploits

WSO2 Management Console suffers from a cross site scripting vulnerability Many different product versions are affected ...

Github Repositories

Proof of concept exploit for CVE-2022-29548: A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, …

Proof of concept exploit for CVE-2022-29548: A reflected XSS issue exists in the Management Console of several WSO2 products This affects API Manager 220, 250, 260, 300, 310, 320, and 400; API Manager Analytics 220, 250, and 260; API Microgateway 220; Data Analytics Server 320; Enterprise Integrator 620, 630, 640, 650, and 660; IS as Key Manag