6.1
CVE-2025-8591
- EPSS 0.16%
- Veröffentlicht 06.07.2026 10:16:53
- Zuletzt bearbeitet 09.07.2026 13:04:39
- CVE-Watchlists
- Unerledigt
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2 ≫ Api Control Plane Version >= 4.5.0 < 4.5.0.44
Wso2 ≫ Api Control Plane Version >= 4.6.0 < 4.6.0.8
Wso2 ≫ Api Manager Version >= 3.1.0 < 3.1.0.355
Wso2 ≫ Api Manager Version >= 3.2.0 < 3.2.0.459
Wso2 ≫ Api Manager Version >= 3.2.1 < 3.2.1.78
Wso2 ≫ Api Manager Version >= 4.0.0 < 4.0.0.380
Wso2 ≫ Api Manager Version >= 4.1.0 < 4.1.0.243
Wso2 ≫ Api Manager Version >= 4.2.0 < 4.2.0.183
Wso2 ≫ Api Manager Version >= 4.3.0 < 4.3.0.94
Wso2 ≫ Api Manager Version >= 4.4.0 < 4.4.0.58
Wso2 ≫ Api Manager Version >= 4.5.0 < 4.5.0.43
Wso2 ≫ Api Manager Version >= 4.6.0 < 4.6.0.7
Wso2 ≫ Identity Server Version >= 5.10.0 < 5.10.0.384
Wso2 ≫ Identity Server Version >= 6.0.0 < 6.0.0.255
Wso2 ≫ Identity Server Version >= 7.0.0 < 7.0.0.131
Wso2 ≫ Identity Server Version >= 7.1.0 < 7.1.0.51
Wso2 ≫ Identity Server As Key Manager Version >= 5.10.0 < 5.10.0.375
Wso2 ≫ Open Banking Am Version >= 2.0.0 < 2.0.0.404
Wso2 ≫ Open Banking Iam Version >= 2.0.0 < 2.0.0.424
Wso2 ≫ Traffic Manager Version >= 4.5.0 < 4.5.0.42
Wso2 ≫ Traffic Manager Version >= 4.6.0 < 4.6.0.7
Wso2 ≫ Universal Gateway Version >= 4.5.0 < 4.5.0.42
Wso2 ≫ Universal Gateway Version >= 4.6.0 < 4.6.0.7
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.057 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| ed10eef1-636d-4fbe-9993-6890dfa878f8 | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4343/