CVE-2023-50069
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Dec 29, 2023
Updated: Jan 5, 2024
CWE ID 79
Summary
CVE-2023-50069 is a stored cross-site scripting (XSS) vulnerability affecting WireMock GUI versions 3.2.0.0 to 3.0.4.0. An attacker can exploit this issue by hosting a malicious payload and using it as a test mapping in the recording feature. The result is rendered in the Body area of the Matched page, leading to the execution of the attacker's payload. This vulnerability occurs due to insufficient validation and sanitization of the response body.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Wiremock
Affected Vendors
- WireMock