WSO2 Products Reflected Cross-Site Scripting Vulnerability in Authentication Endpoint

Vulnerability

A reflected cross-site scripting vulnerability has been identified in the authentication endpoint of multiple WSO2 products. This issue arises from inadequate output encoding of user-supplied input, allowing malicious actors to inject arbitrary JavaScript into the authentication process. Exploitation of this vulnerability could result in user interface modifications, redirections to harmful websites, or data exfiltration from the browser. Although this vulnerability could enable manipulation of the user's browser, session-related sensitive cookies are safeguarded with the httpOnly flag, preventing session hijacking.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
4.2
exploitability
6.5
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.