{"id":"GHSA-rfq3-wpjh-ppvg","summary":"WSO2 Registry Stored Cross Site Scripting (XSS) vulnerability","details":"WSO2 Registry has been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.\n","aliases":["CVE-2023-6911"],"modified":"2024-02-16T08:11:33.398904Z","published":"2023-12-22T18:30:30Z","database_specific":{"github_reviewed_at":"2023-12-22T21:31:02Z","nvd_published_at":"2023-12-18T09:15:05Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6911"},{"type":"WEB","url":"https://github.com/wso2/carbon-registry/commit/878fc7e53c90acc85e303d2af73440014a68b246"},{"type":"WEB","url":"https://github.com/wso2/carbon-registry"},{"type":"WEB","url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1225"}],"affected":[{"package":{"name":"org.wso2.carbon.registry:carbon-registry","ecosystem":"Maven","purl":"pkg:maven/org.wso2.carbon.registry/carbon-registry"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.37"}]}],"versions":["4.6.11","4.6.12","4.6.13","4.6.14","4.6.15","4.6.16","4.6.17","4.6.18","4.6.19","4.6.20","4.6.21","4.6.22","4.6.23","4.6.24","4.6.25","4.6.26","4.6.27","4.6.28","4.6.29","4.6.30","4.6.31","4.6.32","4.6.33","4.6.34","4.6.35","4.6.36","4.6.37","4.6.38","4.6.39","4.6.40","4.6.41","4.6.42","4.7.13","4.7.14","4.7.15","4.7.16","4.7.17","4.7.25","4.7.26","4.7.27","4.7.28","4.7.31","4.7.32","4.7.33","4.7.34","4.7.35","4.7.36"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-rfq3-wpjh-ppvg/GHSA-rfq3-wpjh-ppvg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}