CVE Database
/

CVE-2025-10853

Back to search

CVE-2025-10853

Published: Nov 5, 2025

Modified: Nov 5, 2025

PUBLISHED

CVSS v3.1

5.2

MEDIUM

Description

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, a malicious actor can inject arbitrary JavaScript into the response, leading to reflected XSS. Successful exploitation could result in UI manipulation, redirection to malicious websites, or data theft from the browser. However, session-related sensitive cookies are protected with the httpOnly flag, which mitigates the risk of session hijacking.

VendorProductVersions

WSO2

WSO2 Open Banking IAM

unknown
0 - < 2.0.0
affected
2.0.0 - < 2.0.0.413

WSO2

WSO2 API Manager

unknown
0 - < 3.1.0
affected
3.1.0 - < 3.1.0.344
affected
3.2.0 - < 3.2.0.445
affected
3.2.1 - < 3.2.1.65
affected
4.0.0 - < 4.0.0.365

+5 more versions

WSO2

WSO2 Identity Server

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.373
affected
5.11.0 - < 5.11.0.417
affected
6.0.0 - < 6.0.0.247
affected
6.1.0 - < 6.1.0.246

+2 more versions

WSO2

WSO2 Open Banking AM

unknown
0 - < 2.0.0
affected
2.0.0 - < 2.0.0.393

WSO2

WSO2 Identity Server as Key Manager

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.363

WSO2

WSO2 Enterprise Integrator

unknown
0 - < 6.6.0
affected
6.6.0 - < 6.6.0.223

WSO2

WSO2 API Control Plane

affected
4.5.0 - < 4.5.0.27

WSO2

WSO2 Universal Gateway

affected
4.5.0 - < 4.5.0.25

WSO2

WSO2 Traffic Manager

affected
4.5.0 - < 4.5.0.25

WSO2

org.wso2.carbon.registry:org.wso2.carbon.registry.info.ui

affected
4.7.32 - < 4.7.32.14
affected
4.7.35 - < 4.7.35.11
affected
4.7.39 - < 4.7.39.9
affected
4.7.51 - < 4.7.51.4
affected
4.8.3 - < 4.8.3.9

+5 more versions

WSO2

org.wso2.carbon.registry:org.wso2.carbon.registry.resource.ui

affected
4.7.24 - < 4.7.24.7
affected
4.7.32 - < 4.7.32.14
affected
4.7.33 - < 4.7.33.13
affected
4.7.35 - < 4.7.35.11
affected
4.7.39 - < 4.7.39.9

+10 more versions

WSO2

org.wso2.carbon.governance:org.wso2.carbon.governance.wsdltool.ui

affected
4.8.19 - < 4.8.19.5
affected
4.8.21 - < 4.8.21.9
affected
4.8.28 - < 4.8.28.3
affected
4.8.30 - < 4.8.30.3
affected
4.8.32 - < 4.8.32.1

+3 more versions

WSO2

org.wso2.carbon.identity.inbound.auth.oauth2:org.wso2.carbon.identity.oauth.ui

affected
6.4.2 - < 6.4.2.165
affected
6.4.111 - < 6.4.111.155
affected
6.4.176 - < 6.4.176.28
affected
6.4.180 - < 6.4.180.12
affected
6.9.6 - < 6.9.6.26

+5 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now