Vulnerability record · CVE-2022-39810 · published 9 September 2022
CVE-2022-39810: WSO2 Enterprise Integrator Management Console reflected XSS via driver parameter
Wso2 · Enterprise Integrator
WSO2 Enterprise Integrator 6.4.0 contains a reflected cross-site scripting flaw in the Management Console endpoint /carbon/ndatasource/validateconnection/ajaxprocessor.jsp, reached through the driver parameter. Because the response reflects attacker-controlled input, a crafted link can execute script in a victim's browser within the console's origin. The record states session hijacking or similar attacks would not be possible, which limits the practical severity.
Description
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.jsp via the driver parameter. Session hijacking or similar attacks would not be possible.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS 6.1 medium with user interaction required and no confirmed exploitation, but a high EPSS score and an internet-exposed administrative console keep it worth prompt attention.
What it is
WSO2 Enterprise Integrator 6.4.0 contains a reflected cross-site scripting flaw in the Management Console endpoint /carbon/ndatasource/validateconnection/ajaxprocessor.jsp, reached through the driver parameter. Because the response reflects attacker-controlled input, a crafted link can execute script in a victim's browser within the console's origin. The record states session hijacking or similar attacks would not be possible, which limits the practical severity.
Impact
An attacker can run script in the context of a logged-in Management Console user, enabling actions such as content spoofing, credential phishing within the console, or forced requests on the victim's behalf. The record explicitly rules out session hijacking or comparable attacks.
Attack surface
Network-reachable HTTP endpoint on the Management Console; the CVSS vector shows no privileges required but user interaction required (UI:R), so a victim must open a crafted link while authenticated to the console.
Exploitation
Not listed in CISA KEV and no public exploit or PoC is referenced; only third-party advisory references are present. EPSS is high (0.57253, 99th percentile), indicating elevated predicted exploitation likelihood despite the absence of confirmed in-the-wild activity.
What to do
- Upgrade WSO2 Enterprise Integrator to a release that fixes the reflected XSS in the Management Console, or apply the vendor's patch for 6.4.0.
- Restrict network access to the Management Console (/carbon) to trusted administrative networks or VPN.
- Deploy a WAF rule that blocks script payloads in the driver parameter on /carbon/ndatasource/validateconnection/ajaxprocessor.jsp.
- Ensure console output encoding and input validation are enforced for the driver parameter if patching is delayed.
Detection
- Search web and proxy logs for requests to /carbon/ndatasource/validateconnection/ajaxprocessor.jsp with script-like content in the driver parameter.
- Alert on reflected payload patterns (script tags, event handlers, javascript: URIs) in query strings hitting Management Console endpoints.
- Monitor for unexpected outbound or inline script execution originating from Management Console pages in browser or endpoint telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.gruppotim.it/it/footer/red-team.html | Third Party Advisory |
| https://www.gruppotim.it/it/footer/red-team.html | Third Party Advisory |
Track CVE-2022-39810 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-39810), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.