CVE-2024-7074
- EPSS 9.76%
- Veröffentlicht 02.06.2025 16:42:19
- Zuletzt bearbeitet 15.04.2026 00:35:42
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location on th...
CVE-2024-7097
- EPSS 0.54%
- Veröffentlicht 30.05.2025 15:04:09
- Zuletzt bearbeitet 06.10.2025 13:51:05
An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious act...
CVE-2024-7096
- EPSS 0.59%
- Veröffentlicht 30.05.2025 14:54:32
- Zuletzt bearbeitet 03.12.2025 08:15:47
A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions only when all of the following conditions are met: * SOAP ...
CVE-2024-5962
- EPSS 0.21%
- Veröffentlicht 22.05.2025 19:34:05
- Zuletzt bearbeitet 06.10.2025 13:57:57
A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due to missing output encoding of user-supplied input. A malicious actor can exploit this vulnerability to inject arbitrary JavaScrip...
CVE-2024-6914
- EPSS 0.57%
- Veröffentlicht 22.05.2025 18:26:15
- Zuletzt bearbeitet 06.10.2025 13:56:53
An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin service. A malicious actor can exploit this vulnerability to reset the password of any user account, lea...
CVE-2025-2905
- EPSS 1.15%
- Veröffentlicht 05.05.2025 09:15:15
- Zuletzt bearbeitet 16.10.2025 12:15:47
Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products. A successful XXE attack could allow a remote, unauthentic...
CVE-2024-5848
- EPSS 0.22%
- Veröffentlicht 27.02.2025 08:15:30
- Zuletzt bearbeitet 06.10.2025 13:55:43
A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper input validation. User-supplied data is directly included in server responses from vulnerable service endpoints without proper sanitization or encod...
CVE-2024-2321
- EPSS 0.22%
- Veröffentlicht 27.02.2025 05:15:13
- Zuletzt bearbeitet 03.10.2025 16:29:15
An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token instead of the expected access token. Due to improper authorization checks and token mapping, session coo...
CVE-2023-6911
- EPSS 0.41%
- Veröffentlicht 18.12.2023 09:15:05
- Zuletzt bearbeitet 21.11.2024 08:44:49
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console....
CVE-2023-6839
- EPSS 0.53%
- Veröffentlicht 15.12.2023 11:15:48
- Zuletzt bearbeitet 21.11.2024 08:44:39
Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.