CVE Database
/

CVE-2024-1440

Back to search

CVE-2024-1440

Published: Jun 2, 2025

Modified: Jun 2, 2025

PUBLISHED

CVSS v3.1

5.4

MEDIUM

Description

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site. By exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.

VendorProductVersions

WSO2

WSO2 Identity Server

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.278
affected
5.11.0 - < 5.11.0.347
affected
6.0.0 - < 6.0.0.185
affected
6.1.0 - < 6.1.0.145

+1 more versions

WSO2

WSO2 API Manager

unknown
0 - < 3.1.0
affected
3.1.0 - < 3.1.0.262
affected
3.2.0 - < 3.2.0.344
affected
4.0.0 - < 4.0.0.296

WSO2

WSO2 Identity Server as Key Manager

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.298

WSO2

WSO2 Open Banking AM

unknown
0 - < 2.0.0
affected
2.0.0 - < 2.0.0.308

WSO2

WSO2 Open Banking IAM

unknown
0 - < 2.0.0
affected
2.0.0 - < 2.0.0.327

WSO2

WSO2 Carbon Identity Application Authentication Endpoint(Utils)

affected
5.17.5 - < 5.17.5.256
affected
5.18.187 - < 5.18.187.257
affected
5.23.8 - < 5.23.8.174
affected
5.25.92 - < 5.25.92.77
affected
7.0.78 - < 7.0.78.18

+1 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now