7.8.103
8 years ago
2 months ago
Known vulnerabilities in the org.wso2.carbon.identity.framework:org.wso2.carbon.identity.user.store.configuration.ui package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.user.store.configuration.ui is an User Store UI component for WSO2 Carbon Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to insufficient output encoding in error messages generated by the JDBC user store connection validation request. An attacker can redirect the browser to a malicious website, make changes in the UI of the web page, retrieve information from the browser, or cause harm otherwise. Note:
Since all session-related sensitive cookies are protected with the How to fix Cross-site Scripting (XSS)? Upgrade | [,7.5.12) |