WSO2 Identity Server
cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*
- 7.0.0
A reflected cross-site scripting vulnerability has been identified in WSO2 Identity Server version 7.0.0, specifically within the sub-organization login process. This vulnerability arises from inadequate input validation, allowing malicious actors to inject arbitrary JavaScript. Exploitation could result in unauthorized modifications to the user interface, redirection to harmful websites, or exfiltration of data from the user's browser. Although this vulnerability could enable manipulation of the user's browser, session-related sensitive cookies are safeguarded with the httpOnly flag, mitigating the risk of session hijacking.
Exploitation of this vulnerability could lead to reflected cross-site scripting, allowing for the injection of malicious scripts that could be executed in the context of the user's browser.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.