CVE-2023-6911: XSS

Published Dec 18, 2023
·
Updated

Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.

Other sources

WSO2 Registry has been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.

Affected Software

36 affected componentsFixes available
maven/org.wso2.carbon.registry:carbon-registry<4.7.37
4.7.37
WSO2 API Manager=2.2.0
WSO2 API Manager=2.5.0
WSO2 API Manager=2.6.0
WSO2 API Manager=3.0.0
WSO2 API Manager=3.1.0
WSO2 API Manager=3.2.0
WSO2 API Manager Analytics=2.2.0
WSO2 API Manager Analytics=2.5.0
WSO2 API Microgateway=2.2.0
WSO2 Data Analytics Server=3.2.0
WSO2 Enterprise Integrator=6.1.0
WSO2 Enterprise Integrator=6.1.1
WSO2 Enterprise Integrator=6.2.0
WSO2 Enterprise Integrator=6.3.0
WSO2 Enterprise Integrator=6.4.0
WSO2 Enterprise Integrator=6.5.0
WSO2 Enterprise Integrator=6.6.0
WSO2 Identity Server as Key Manager=5.5.0
WSO2 Identity Server as Key Manager=5.6.0
WSO2 Identity Server as Key Manager=5.7.0
WSO2 Identity Server as Key Manager=5.9.0
WSO2 Identity Server as Key Manager=5.10.0
WSO2 Identity Server=5.4.0
WSO2 Identity Server=5.4.1
WSO2 Identity Server=5.5.0
WSO2 Identity Server=5.6.0
WSO2 Identity Server=5.7.0
WSO2 Identity Server=5.8.0
WSO2 Identity Server=5.9.0
WSO2 Identity Server=5.10.0
WSO2 Identity Server Analytics=5.4.0
WSO2 Identity Server Analytics=5.4.1
WSO2 Identity Server Analytics=5.5.0
WSO2 Identity Server Analytics=5.6.0
Wso2 Message Broker=3.2.0

Remediation

Information

For WSO2 Subscription holders, the recommended solution is to apply the provided patch/update to the affected versions of the products. If there are any instructions given with the patch/update, please make sure those are followed properly. Community users may apply the relevant fixes to the product based on the public fix(s) advertised in  https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1... https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1225/

Event History

Dec 18, 2023
CVE Published
08:32 AM
Data Sourced
08:32 AM
RemedyDescriptionSeverityWeakness
Dec 22, 2023
Advisory Published
06:30 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-6911?

CVE-2023-6911 is classified as a High severity vulnerability due to its potential for Stored Cross Site Scripting (XSS) attacks.

2

How do I fix CVE-2023-6911?

To resolve CVE-2023-6911, update the affected WSO2 products to versions that include the fix, specifically versions above the vulnerable package version 4.7.37.

3

Which WSO2 products are affected by CVE-2023-6911?

CVE-2023-6911 affects multiple WSO2 products, including WSO2 API Manager, WSO2 Enterprise Integrator, and WSO2 Identity Server, among others.

4

What impact does CVE-2023-6911 have on WSO2 systems?

The impact of CVE-2023-6911 includes the potential for attackers to inject malicious scripts into the Registry feature of the Management Console, compromising the security of the application.

5

Is there a workaround for CVE-2023-6911 until a fix is applied?

Currently, applying available patches is the recommended approach, as there are no known effective workarounds for mitigating the vulnerability in CVE-2023-6911.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203