CVE-2018-8716: XSS
Published Apr 25, 2018
·Updated
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
Affected Software
1 affected component
WSO2 Identity Server<5.5.0
Event History
Apr 25, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-8716?
CVE-2018-8716 is a vulnerability in WSO2 Identity Server before version 5.5.0 that allows low-privileged attackers to perform XSS attacks via the dashboard.
2
How severe is CVE-2018-8716?
CVE-2018-8716 has a severity rating of 5.4 out of 10, which is considered medium.
3
What is the affected software for CVE-2018-8716?
The affected software for CVE-2018-8716 is WSO2 Identity Server versions up to and excluding 5.5.0.
4
How can I fix CVE-2018-8716?
To fix CVE-2018-8716, it is recommended to upgrade WSO2 Identity Server to version 5.5.0 or later.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-8716?
The CWE ID for CVE-2018-8716 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').