WSO2 API Manager Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WSO2 API Manager developer portal. This issue arises because the portal does not properly validate user input or encode output, allowing malicious actors to inject script content that is executed in the context of the user's browser. Exploitation of this vulnerability could lead to redirection to a malicious website, unauthorized changes to the web page's user interface, or retrieval of information from the browser. However, session hijacking is not possible, as sensitive session cookies are protected by the httpOnly flag.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the context of the user's browser. This could result in redirection to malicious websites, unauthorized UI modifications, or access to browser-stored information. However, session hijacking is not feasible due to the httpOnly flag on sensitive cookies.

Remediation

WSO2 API Manager users should update to version 4.1.0 (update level 187), 4.0.0 (update level 293), 3.2.1 (update level 32), or 3.2.0 (update level 408).

Added: Apr 16, 2026, 10:23 AM
Updated: Apr 16, 2026, 10:23 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
6.4
remediation
7.7
relevance
6.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.