Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability the attacker can hijack a logged-in user’s session by stealing cookies which means that a malicious hacker can change the logged-in user’s password and invalidate the session of the victim while the hacker maintains access.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-20378 Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability the attacker can hijack a logged-in user’s session by stealing cookies which means that a malicious hacker can change the logged-in user’s password and invalidate the session of the victim while the hacker maintains access.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T16:25:43.707Z

Reserved: 2020-10-27T00:00:00

Link: CVE-2020-27885

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-29T21:15:15.957

Modified: 2024-11-21T05:21:58.937

Link: CVE-2020-27885

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.