← Voltar para CVEs
CVE-2024-5962
MEDIUM6.1
Descricao
A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due to missing output encoding of user-supplied input. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript into the authentication flow, potentially leading to UI modifications, redirections to malicious websites, or data exfiltration from the browser. While this issue could allow an attacker to manipulate the user’s browser, session-related sensitive cookies remain protected with the httpOnly flag, preventing session hijacking.
Detalhes CVE
Pontuacao CVSS v3.16.1
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioREQUIRED
Publicado5/22/2025
Ultima modificacao10/6/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
wso2:api_managerwso2:identity_server
Fraquezas (CWE)
CWE-79
Referencias
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3443/(ed10eef1-636d-4fbe-9993-6890dfa878f8)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.