First published: Thu Oct 29 2020(Updated: )
WSO2 Enterprise Integrator 6.6.0 or earlier contains a stored cross-site scripting (XSS) vulnerability in BPMN explorer tasks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WSO2 Enterprise Integrator | <=6.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25516 is a stored cross-site scripting (XSS) vulnerability found in WSO2 Enterprise Integrator 6.6.0 or earlier in the BPMN explorer tasks.
CVE-2020-25516 has a severity score of 5.4, which is considered medium.
WSO2 Enterprise Integrator versions up to and including 6.6.0 are impacted by CVE-2020-25516.
To fix the CVE-2020-25516 vulnerability, it is recommended to update WSO2 Enterprise Integrator to a version that is not affected.
More information about CVE-2020-25516 can be found in the WSO2 Security Advisory and the Proof-of-Concepts GitHub repository.