CVE-2025-5770 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encoding. A malici…
Medium CVSS: 6.1

CVE-2025-5770

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encoding. A malicious actor can inject arbitrary JavaScript payloads into the authentication endpoint, which are reflected back in the response, enabling browser-based attacks.

Exploitation may result in redirection to malicious websites, UI manipulation, or unauthorized data access from the victim’s browser. However, session-related cookies are protected with the httpOnly flag, which mitigates session hijacking via this vector.
Vendor
Wso2
Product
Api Control Plane
CWE
CWE-79
Yayın Tarihi
2025-11-05 19:16:01
Güncelleme
2025-11-13 15:32:16
Source Identifier
ed10eef1-636d-4fbe-9993-6890dfa878f8
KEV Date Added
-

Kategoriler

Referanslar