/WSO2-2021-1261

WSO2-2021-1261: Multiple Cross-Site Scripting in WSO2 ESB

WSO2-2021-1261: Multiple Cross-Site Scripting in WSO2 ESB

Due to improper output encoding, multiple Cross Site Scripting (XSS) attacks have been identified in WSO2 ESB.

Vendor Disclosure:

The vendor's disclosure and fix for this vulnerability can be found here.

Why no CVE?

Neither me nor the vendor requested a CVE for this vulnerability.

Requirements:

This vulnerability requires:

  • Some XSSs require valid user credentials

Proof Of Concept:

More details and the exploitation process can be found in this PDF.