« Volver al listado

CVE-2023-6838

Estado: ModificadaMedia (6.1)—

Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated and unauthenticated requests.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-6838",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
      "affectedData": [
        {
          "repo": "https://github.com/wso2/product-apim",
          "vendor": "WSO2",
          "product": "WSO2 API Manager",
          "versions": [
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "3.1.0.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.1.0.0",
              "lessThan": "3.1.0.14",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.2.0.0",
              "lessThan": "3.2.0.10",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://github.com/wso2/product-is",
          "vendor": "WSO2",
          "product": "WSO2 Identity Server",
          "versions": [
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "5.10.0.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.10.0.0",
              "lessThan": "5.10.0.5",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 IS as Key Manager",
          "versions": [
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "5.10.0.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.10.0.0",
              "lessThan": "5.10.0.5",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-15T10:15:10.000",
  "references": [
    {
      "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1233/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
    },
    {
      "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1233/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated and unauthenticated requests.\n\n"
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad XSS reflejada se puede explotar alterando un parámetro de solicitud en el endpoint de autenticación. Esto se puede realizar tanto en solicitudes autenticadas como no autenticadas."
    }
  ],
  "lastModified": "2026-06-17T06:51:30.920",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1344FB79-0796-445C-A8F3-C03E995925D1"
            },
            {
              "criteria": "cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E31E32CD-497E-4EF5-B3FC-8718EE06EDAD"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wso2:identity_server_as_key_manager:5.10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6BB34405-A2F1-461A-B51B-E103BB3680A1"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4F126CA-A2F9-44F4-968B-DF71765869E5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}