6.1

CVE-2025-8591

Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application.

By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2Api Control Plane Version >= 4.5.0 < 4.5.0.44
Wso2Api Control Plane Version >= 4.6.0 < 4.6.0.8
Wso2Api Manager Version >= 3.1.0 < 3.1.0.355
Wso2Api Manager Version >= 3.2.0 < 3.2.0.459
Wso2Api Manager Version >= 3.2.1 < 3.2.1.78
Wso2Api Manager Version >= 4.0.0 < 4.0.0.380
Wso2Api Manager Version >= 4.1.0 < 4.1.0.243
Wso2Api Manager Version >= 4.2.0 < 4.2.0.183
Wso2Api Manager Version >= 4.3.0 < 4.3.0.94
Wso2Api Manager Version >= 4.4.0 < 4.4.0.58
Wso2Api Manager Version >= 4.5.0 < 4.5.0.43
Wso2Api Manager Version >= 4.6.0 < 4.6.0.7
Wso2Identity Server Version >= 5.10.0 < 5.10.0.384
Wso2Identity Server Version >= 6.0.0 < 6.0.0.255
Wso2Identity Server Version >= 7.0.0 < 7.0.0.131
Wso2Identity Server Version >= 7.1.0 < 7.1.0.51
Wso2Identity Server As Key Manager Version >= 5.10.0 < 5.10.0.375
Wso2Open Banking Am Version >= 2.0.0 < 2.0.0.404
Wso2Open Banking Iam Version >= 2.0.0 < 2.0.0.424
Wso2Traffic Manager Version >= 4.5.0 < 4.5.0.42
Wso2Traffic Manager Version >= 4.6.0 < 4.6.0.7
Wso2Universal Gateway Version >= 4.5.0 < 4.5.0.42
Wso2Universal Gateway Version >= 4.6.0 < 4.6.0.7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.057
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
ed10eef1-636d-4fbe-9993-6890dfa878f8 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4343/
Vendor Advisory