WSO2 Management Console (Multiple Products) – Unauthenticated Reflected Cross-Site Scripting (XSS)
WSO2 Management Console is vulnerable to unauthenticated reflected cross-site scripting (XSS) attacks. An attacker can craft a malicious URL and send it to an unsuspecting user. When the user clicks on the link, the malicious payload is executed in the user's browser. Affected versions include API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0 and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; WSO2 Micro Integrator 1.0.0.