CVE-2025-1862
- EPSS 0.28%
- Veröffentlicht 26.09.2025 09:15:31
- Zuletzt bearbeitet 06.10.2025 13:43:41
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a...
CVE-2024-3511
- EPSS 0.04%
- Veröffentlicht 23.06.2025 08:47:55
- Zuletzt bearbeitet 06.10.2025 13:35:40
An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploi...
CVE-2024-8008
- EPSS 0.04%
- Veröffentlicht 02.06.2025 16:48:12
- Zuletzt bearbeitet 06.10.2025 13:51:36
A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store connection validation request. A malicious actor can inject a specially craft...
CVE-2024-3509
- EPSS 0.04%
- Veröffentlicht 02.06.2025 16:44:28
- Zuletzt bearbeitet 06.10.2025 13:48:27
A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor within the registry section. To exploit this vulnerability, a malicious actor mu...
CVE-2024-7074
- EPSS 0.1%
- Veröffentlicht 02.06.2025 16:42:19
- Zuletzt bearbeitet 02.06.2025 17:32:17
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location on th...
CVE-2024-0392
- EPSS 0.04%
- Veröffentlicht 27.02.2025 07:15:32
- Zuletzt bearbeitet 06.10.2025 13:55:23
A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF token validation. This flaw allows attackers to craft malicious requests that can trigger state-changing...
CVE-2023-6911
- EPSS 0.35%
- Veröffentlicht 18.12.2023 09:15:05
- Zuletzt bearbeitet 21.11.2024 08:44:49
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console....
CVE-2023-6836
- EPSS 0.17%
- Veröffentlicht 15.12.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 08:44:38
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
CVE-2022-39810
- EPSS 2.1%
- Veröffentlicht 09.09.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:18:17
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.jsp via the driver parameter. S...
CVE-2022-39809
- EPSS 0.23%
- Veröffentlicht 09.09.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:18:17
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/mediation_secure_vault/properties/ajaxprocessor.jsp via the name parameter. ...