← Back

CVE-2025-4760

nvd nist
Published: Sep 23, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8 (Secondary)

Description

An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper validation of user-supplied input during API document upload in the Publisher portal. A user with publisher privileges can upload a crafted API document containing malicious JavaScript, which is later rendered in the browser when accessed by other users. A successful attack could result in redirection to malicious websites, unauthorized UI modifications, or exfiltration of browser-accessible data. However, session-related sensitive cookies are protected by the httpOnly flag, preventing session hijacking.

Affected (10)

4 products
Api Control Plane
Api Manager
Traffic Manager
Universal Gateway
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.5.0
Wso2
Version 3.2.0
Version 3.2.1
Version 4.1.0
Version 4.2.0
Version 4.3.0
Version 4.4.0
Version 4.5.0
Version 4.5.0
Version 4.5.0

References (1)

Timeline

No history available yet.