CVE-2023-6911: XSS
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
Other sources
WSO2 Registry has been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6911?
CVE-2023-6911 is classified as a High severity vulnerability due to its potential for Stored Cross Site Scripting (XSS) attacks.
How do I fix CVE-2023-6911?
To resolve CVE-2023-6911, update the affected WSO2 products to versions that include the fix, specifically versions above the vulnerable package version 4.7.37.
Which WSO2 products are affected by CVE-2023-6911?
CVE-2023-6911 affects multiple WSO2 products, including WSO2 API Manager, WSO2 Enterprise Integrator, and WSO2 Identity Server, among others.
What impact does CVE-2023-6911 have on WSO2 systems?
The impact of CVE-2023-6911 includes the potential for attackers to inject malicious scripts into the Registry feature of the Management Console, compromising the security of the application.
Is there a workaround for CVE-2023-6911 until a fix is applied?
Currently, applying available patches is the recommended approach, as there are no known effective workarounds for mitigating the vulnerability in CVE-2023-6911.