CVE Database
/

CVE-2024-3509

Back to search

CVE-2024-3509

Published: Jun 2, 2025

Modified: Jun 2, 2025

PUBLISHED

CVSS v3.1

4.3

MEDIUM

Description

A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor within the registry section. To exploit this vulnerability, a malicious actor must have a valid user account with administrative access to the Management Console. If successful, the actor could inject persistent JavaScript payloads, enabling the theft of user data or execution of unauthorized actions on behalf of other users. While this issue enables persistent client-side script execution, session-related cookies remain protected with the httpOnly flag, preventing session hijacking.

VendorProductVersions

WSO2

WSO2 Enterprise Integrator

unknown
0 - < 6.6.0
affected
6.6.0 - < 6.6.0.202

WSO2

WSO2 API Manager

unknown
0 - < 3.1.0
affected
3.1.0 - < 3.1.0.275
affected
3.2.0 - < 3.2.0.392
affected
3.2.1 - < 3.2.1.19
affected
4.0.0 - < 4.0.0.308

+3 more versions

WSO2

WSO2 Open Banking AM

unknown
0 - < 2.0.0
affected
2.0.0 - < 2.0.0.325

WSO2

WSO2 Open Banking IAM

unknown
0 - < 2.0.0
affected
2.0.0 - < 2.0.0.345

WSO2

WSO2 Identity Server as Key Manager

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.292

WSO2

WSO2 Identity Server

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.296
affected
5.11.0 - < 5.11.0.333
affected
6.0.0 - < 6.0.0.181
affected
6.1.0 - < 6.1.0.142

+1 more versions

WSO2

WSO2 Carbon Registry Resources UI

affected
4.7.24 - < 4.7.24.6
affected
4.7.32 - < 4.7.32.10
affected
4.7.33 - < 4.7.33.8
affected
4.7.35 - < 4.7.35.8
affected
4.7.39 - < 4.7.39.6

+8 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

High

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now