Dismissed
(no matching packages found)
Permalink
CVE-2025-8591
6.1 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Changed (C)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
Activity log
- Created & dismissed (no matching packages found) suggestion
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.
References
Affected products
WSO2 API Manager
- <4.6.0.7
- <4.2.0.183
- <4.0.0.380
- <4.3.0.94
- <4.5.0.43
- <3.1.0
- <4.1.0.243
- <3.1.0.355
- <4.4.0.58
- <3.2.1.78
- <3.2.0.459
WSO2 Identity Server
- <7.1.0.51
- <7.1.0.21
- <5.10.0.381
- <7.0.0.131
- <6.0.0.255
- <5.10.0
- <5.10.0.384
WSO2 Open Banking AM
- <2.0.0
- <2.0.0.404
WSO2 Traffic Manager
- <4.5.0.42
- <4.6.0.7
WSO2 Open Banking IAM
- <2.0.0.424
- <2.0.0
WSO2 API Control Plane
- <4.6.0.8
- <4.5.0.44
WSO2 Universal Gateway
- <4.5.0.42
- <4.6.0.7
WSO2 Identity Server as Key Manager
- <5.10.0
- <5.10.0.375