WSO2 Management Console through 5.10 is susceptible to reflected cross-site scripting which can be exploited by tampering a request parameter in Management Console. This can be performed in both authenticated and unauthenticated requests.
View the template here CVE-2020-17453.yaml
References:
https://github.com/ARPSyndicate/cvemon