CVE-2022-39809: XSS
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/mediationsecurevault/properties/ajaxprocessor.jsp via the name parameter. Session hijacking or similar attacks would not be possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39809?
The severity of CVE-2022-39809 is medium with a CVSS score of 6.1.
What is the affected software for CVE-2022-39809?
The affected software for CVE-2022-39809 is WSO2 Enterprise Integrator version 6.4.0.
What is the vulnerability description for CVE-2022-39809?
CVE-2022-39809 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Management Console of WSO2 Enterprise Integrator 6.4.0.
How can the Reflected Cross-Site Scripting (XSS) vulnerability be exploited?
The Reflected Cross-Site Scripting (XSS) vulnerability in CVE-2022-39809 can be exploited by injecting malicious code through the 'name' parameter in the Management Console.
Are there any known mitigations for CVE-2022-39809?
At this time, there are no known mitigations for CVE-2022-39809. It is recommended to update to a patched version of WSO2 Enterprise Integrator.