WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
https://twitter.com/JacksonHHax/status/1374681422678519813
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1132/
https://github.com/JHHAX/CVE-2020-17453-PoC
Source: Mitre, NVD
Published: 2021-04-05
Updated: 2026-06-17
Base Score: 4.3
Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N
Severity: Medium
Base Score: 6.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS: 0.26118