CVE-2024-3509
Last modified
CVE-2024-3509 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor within the registry section. To exploit this vulnerability, a malicious actor must have a valid user account with administrative access to the Management Console. If successful, the actor could inject persistent JavaScript payloads, enabling the theft of user data or execution of unauthorized actions on behalf of other users. While this issue enables persistent client-side script execution, session-related cookies remain protected with the httpOnly flag, preventing session hijacking.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor within the registry section. To exploit this vulnerability, a malicious actor must have a valid user account with administrative access to the Management Console. If successful, the actor could inject persistent JavaScript payloads, enabling the theft of user data or execution of unauthorized actions on behalf of other users. While this issue enables persistent client-side script execution, session-related cookies remain protected with the httpOnly flag, preventing session hijacking.
Metrics
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Api Manager | 3.2.0 |
| Wso2 | Api Manager | 3.2.1 |
| Wso2 | Api Manager | 4.0.0 |
| Wso2 | Api Manager | 4.1.0 |
| Wso2 | Api Manager | 4.2.0 |
| Wso2 | Api Manager | 4.3.0 |
| Wso2 | Enterprise Integrator | 6.6.0 |
| Wso2 | Identity Server | 5.10.0 |
| Wso2 | Identity Server | 5.11.0 |
| Wso2 | Identity Server | 6.0.0 |
| Wso2 | Identity Server | 6.1.0 |
| Wso2 | Identity Server | 7.0.0 |
| Wso2 | Identity Server As Key Manager | 5.10.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-3509?
How severe is CVE-2024-3509?
How do I fix CVE-2024-3509?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-35081LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary …7.5
- CVE-2024-35082J2EEFAST v2.7.0 was discovered to contain a SQL injection vu…6.3
- CVE-2024-35083J2EEFAST v2.7.0 was discovered to contain a SQL injection vu…8.8
- CVE-2024-35084J2EEFAST v2.7.0 was discovered to contain a SQL injection vu…9.8
- CVE-2024-35085J2EEFAST v2.7.0 was discovered to contain a SQL injection vu…5.4
- CVE-2024-35086J2EEFAST v2.7.0 was discovered to contain a SQL injection vu…9.8
- CVE-2024-35090J2EEFAST v2.7.0 was discovered to contain a SQL injection vu…8.2
- CVE-2024-35091J2EEFAST v2.7.0 was discovered to contain a SQL injection vu…9.8
- CVE-2024-35099TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to cont…9.8
- CVE-2024-3510Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-35102Insecure Permissions vulnerability in VITEC AvediaServer (Mo…8.8
- CVE-2024-35106NEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a …4.6
Are you affected by CVE-2024-3509?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
