CVE-2020-25516: XSS
Published Oct 29, 2020
·Updated
WSO2 Enterprise Integrator 6.6.0 or earlier contains a stored cross-site scripting (XSS) vulnerability in BPMN explorer tasks.
Affected Software
1 affected component
WSO2 Enterprise Integrator<=6.6.0
Event History
Oct 29, 2020
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
Description
Frequently Asked Questions
1
What is CVE-2020-25516?
CVE-2020-25516 is a stored cross-site scripting (XSS) vulnerability found in WSO2 Enterprise Integrator 6.6.0 or earlier in the BPMN explorer tasks.
2
How severe is CVE-2020-25516?
CVE-2020-25516 has a severity score of 5.4, which is considered medium.
3
Which software versions are affected by CVE-2020-25516?
WSO2 Enterprise Integrator versions up to and including 6.6.0 are impacted by CVE-2020-25516.
4
How can I fix the CVE-2020-25516 vulnerability?
To fix the CVE-2020-25516 vulnerability, it is recommended to update WSO2 Enterprise Integrator to a version that is not affected.
5
Where can I find more information about CVE-2020-25516?
More information about CVE-2020-25516 can be found in the WSO2 Security Advisory and the Proof-of-Concepts GitHub repository.