WSO2 Identity Server Multiple Stored Cross-Site Scripting Vulnerabilities Fixed by 5.5.0
Description
(#Several stored cross-site scripting vulnerabilities were reported in WSO2 Identity Server.#A remote attacker could exploit them by enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript or HTML code.##These vulnerabilities are triggerable via:#- CVE-2018-8716: the "Firstname", "Lastname", "Username" and "Address" fields in the Dashboard#- the Host field (URL) of a new Worker.##Proofs of concept are available.)