← Back

CVE-2021-36760

nvd nist
Published: Dec 7, 2021Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter. Once the username or password reset procedure is completed, the JavaScript code will be executed. (recoverpassword.do also has an open redirect issue for a similar reason.)

Affected (16)

4 products
Api Manager
Identity Server
Identity Server As Key Manager
Iot Server
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
Version 3.0.0
Version 3.1.0
Version 3.2.0
Version 4.0.0
Wso2
Version 5.10.0
Version 5.11.0
Version 5.7.0
Version 5.8.0
Version 5.9.0
Wso2
Version 5.10.0
Version 5.3.0
Version 5.5.0
Version 5.6.0
Version 5.7.0
Version 5.9.0
Version 3.3.1

References (4)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.