← Voltar para CVEs
CVE-2024-4867
MEDIUM5.4
Descricao
The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to inject script content that is executed within the context of a user's browser. By leveraging this cross-site scripting vulnerability, a malicious actor can cause the browser to redirect to a malicious website, make changes to the UI of the web page, or retrieve information from the browser. However, session hijacking is not possible as all session-related sensitive cookies are protected by the httpOnly flag.
Detalhes CVE
Pontuacao CVSS v3.15.4
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioREQUIRED
Publicado4/16/2026
Ultima modificacao4/16/2026
Fontenvd
Avistamentos honeypot0
Fraquezas (CWE)
CWE-79
Referencias
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3391/(ed10eef1-636d-4fbe-9993-6890dfa878f8)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.