CVE Database
/

CVE-2024-4867

Back to search

CVE-2024-4867

Published: Apr 16, 2026

Modified: Apr 16, 2026

PUBLISHED

CVSS v3.1

5.4

MEDIUM

Description

The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to inject script content that is executed within the context of a user's browser. By leveraging this cross-site scripting vulnerability, a malicious actor can cause the browser to redirect to a malicious website, make changes to the UI of the web page, or retrieve information from the browser. However, session hijacking is not possible as all session-related sensitive cookies are protected by the httpOnly flag.

VendorProductVersions

WSO2

WSO2 API Manager

unknown
0 - < 3.2.0
affected
3.2.0 - < 3.2.0.408
affected
3.2.1 - < 3.2.1.32
affected
4.0.0 - < 4.0.0.293
affected
4.1.0 - < 4.1.0.187

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now