CVE-2023-31664

CVSS V2 None CVSS V3 None
Description
A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tenantDomain parameter.
Overview
  • CVE ID
  • CVE-2023-31664
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Received
  • Published Version
  • 2023-05-23T01:15:09
  • Last Modified Date
  • 2023-05-23T01:15:09
History
Created Old Value New Value Data Type Notes
2023-05-23 02:00:34 Added to TrackCVE