Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-50069
HistoryDec 29, 2023 - 9:15 p.m.

Cross site scripting

2023-12-2921:15:00
PRIOn knowledge base
www.prio-n.com
5
wiremock
vulnerability
stored cross-site scripting
recording feature
attacker
malicious payload
test mapping
validation
sanitization
execution

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.8%

WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature. An attacker can host a malicious payload and perform a test mapping pointing to the attacker’s file, and the result will render on the Matched page in the Body area, resulting in the execution of the payload. This occurs because the response body is not validated or sanitized.

CPENameOperatorVersion
wiremockge3.0.4
wiremockle3.2.0

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.8%

Related for PRION:CVE-2023-50069