An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:wso2:identity_server:5.7.0:*:*:*:*:*:*:*",
"cpe:2.3:a:wso2:identity_server:5.8.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "5.7.0"
},
{
"last_affected": "5.7.0"
},
{
"introduced": "5.8.0"
},
{
"last_affected": "5.8.0"
}
],
"vendor_product": "wso2:identity_server"
}
]
}