WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17453
Reference (s):
- https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-1132
- https://github.com/JHHAX/CVE-2020-17453-PoC
- https://twitter.com/JacksonHHax/status/1374681422678519813