← Vulnerability feed

Vulnerability record · CVE-2022-39810 · published 9 September 2022

CVE-2022-39810: WSO2 Enterprise Integrator Management Console reflected XSS via driver parameter

Wso2 · Enterprise Integrator

WSO2 Enterprise Integrator 6.4.0 contains a reflected cross-site scripting flaw in the Management Console endpoint /carbon/ndatasource/validateconnection/ajaxprocessor.jsp, reached through the driver parameter. Because the response reflects attacker-controlled input, a crafted link can execute script in a victim's browser within the console's origin. The record states session hijacking or similar attacks would not be possible, which limits the practical severity.

6.1 CVSS 3.1 Medium EPSS 57% · top 0.9% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.jsp via the driver parameter. Session hijacking or similar attacks would not be possible.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityCVSS 6.1 medium with user interaction required and no confirmed exploitation, but a high EPSS score and an internet-exposed administrative console keep it worth prompt attention.

What it is

WSO2 Enterprise Integrator 6.4.0 contains a reflected cross-site scripting flaw in the Management Console endpoint /carbon/ndatasource/validateconnection/ajaxprocessor.jsp, reached through the driver parameter. Because the response reflects attacker-controlled input, a crafted link can execute script in a victim's browser within the console's origin. The record states session hijacking or similar attacks would not be possible, which limits the practical severity.

Impact

An attacker can run script in the context of a logged-in Management Console user, enabling actions such as content spoofing, credential phishing within the console, or forced requests on the victim's behalf. The record explicitly rules out session hijacking or comparable attacks.

Attack surface

Network-reachable HTTP endpoint on the Management Console; the CVSS vector shows no privileges required but user interaction required (UI:R), so a victim must open a crafted link while authenticated to the console.

Exploitation

Not listed in CISA KEV and no public exploit or PoC is referenced; only third-party advisory references are present. EPSS is high (0.57253, 99th percentile), indicating elevated predicted exploitation likelihood despite the absence of confirmed in-the-wild activity.

What to do

  • Upgrade WSO2 Enterprise Integrator to a release that fixes the reflected XSS in the Management Console, or apply the vendor's patch for 6.4.0.
  • Restrict network access to the Management Console (/carbon) to trusted administrative networks or VPN.
  • Deploy a WAF rule that blocks script payloads in the driver parameter on /carbon/ndatasource/validateconnection/ajaxprocessor.jsp.
  • Ensure console output encoding and input validation are enforced for the driver parameter if patching is delayed.

Detection

  • Search web and proxy logs for requests to /carbon/ndatasource/validateconnection/ajaxprocessor.jsp with script-like content in the driver parameter.
  • Alert on reflected payload patterns (script tags, event handlers, javascript: URIs) in query strings hitting Management Console endpoints.
  • Monitor for unexpected outbound or inline script execution originating from Management Console pages in browser or endpoint telemetry.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-39810 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-29464WSO2 products path traversal file upload leads to RCEMultiple WSO2 products accept unrestricted file uploads through a /fileupload endpoint, and a Content-Disposition directory traversal sequence lets a…KEVEPSS 100%analysed9.1CVE-2025-10713Wso2 api control plane xml external entity (xxe) vulnerabilityAn XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses u…EPSS 0.42%8.8CVE-2025-6670Wso2 api control plane cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operation…EPSS 0.23%8.8CVE-2020-24703Wso2 api manager vulnerabilityAn issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if th…EPSS 1.1%7.5CVE-2023-6836Wso2 api manager xml external entity (xxe) vulnerabilityMultiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used featur…EPSS 0.48%7.2CVE-2025-11093Wso2 api control plane code injection vulnerabilityAn arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Media…EPSS 0.44%7.2CVE-2025-10907Wso2 api control plane unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP ad…EPSS 0.56%7.2CVE-2025-3125Wso2 api control plane unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpo…EPSS 0.85%

Source: NIST National Vulnerability Database (record CVE-2022-39810), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.