← Back

CVE-2025-5770

nvd nist
Published: Nov 5, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8 (Secondary)

Description

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encoding. A malicious actor can inject arbitrary JavaScript payloads into the authentication endpoint, which are reflected back in the response, enabling browser-based attacks. Exploitation may result in redirection to malicious websites, UI manipulation, or unauthorized data access from the victim’s browser. However, session-related cookies are protected with the httpOnly flag, which mitigates session hijacking via this vector.

Affected (9)

3 products
Api Control Plane
Api Manager
Identity Server
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.5.0
Wso2
Version 4.2.0
Version 4.3.0
Version 4.4.0
Version 4.5.0
Wso2
Version 6.0.0
Version 6.1.0
Version 7.0.0
Version 7.1.0

References (1)

Timeline

No history available yet.