Securin Zero-Days

CVE-2020-14444 – Reflected Cross-Site Scripting in WSO2 Product 

Severity:Medium

Vendor

WSO2

Affected Product

WSO2 IS as Key Manager 5.9.0 or earlier, WSO2 Identity Server 5.9.0 or earlier

CVE

CVE-2020-14444

Securin ID

2020-CSW-05-1042

Status

Fixed

Date

February 10, 2020

Description

A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted web site. The application targets your users and not the application itself, but it uses your application as the vehicle for the attack. XSS payload is executed when the user loads a page created in WSO2 Identity Server version 5.9.0 Product.

Proof of Concept (POC):

The following vulnerability was tested on WSO2 Identity Server version 5.9.0 Product.

Issue 01: Persistent Cross-Site scripting.

Figure 01: Navigating to the Policy Administration and Clicking the Add New Entitlement Policy Link.