First published: Tue May 23 2023(Updated: )
A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tenantDomain parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WSO2 API Manager | <4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31664 is a reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before version 4.2.0.
CVE-2023-31664 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tenantDomain parameter, potentially leading to unauthorized access or data theft.
WSO2 API Manager versions up to and excluding 4.2.0 are affected by CVE-2023-31664.
CVE-2023-31664 has a severity rating of medium (6.1).
To fix CVE-2023-31664, it is recommended to upgrade to WSO2 API Manager version 4.2.0 or later.