CVE Database
/

CVE-2024-5962

Back to search

CVE-2024-5962

Published: May 22, 2025

Modified: May 22, 2025

PUBLISHED

CVSS v3.1

6.1

MEDIUM

Description

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due to missing output encoding of user-supplied input. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript into the authentication flow, potentially leading to UI modifications, redirections to malicious websites, or data exfiltration from the browser. While this issue could allow an attacker to manipulate the user’s browser, session-related sensitive cookies remain protected with the httpOnly flag, preventing session hijacking.

VendorProductVersions

WSO2

WSO2 API Manager

affected
4.2.0 - < 4.2.0.94
affected
4.3.0 - < 4.3.0.9

WSO2

WSO2 Identity Server

affected
6.0.0 - < 6.0.0.199
affected
6.1.0 - < 6.1.0.172

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now