216.73.216.197

CVE-2025-10853

· Published 05/11/2025 20:15 · Modified 13/11/2025 15:31

Labels: CVE-2025-10853 2025-11-05CVE-2025-10853CWE-79ed10eef1-636d-4fbe-9993-6890dfa878f8

Essential information

Published
05/11/2025 20:15
Modified
13/11/2025 15:31
Author
Creator
CVSS
5.2 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS metrics

Description

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, a malicious actor can inject arbitrary JavaScript into the response, leading to reflected XSS. Successful exploitation could result in UI manipulation, redirection to malicious websites, or data theft from the browser. However, session-related sensitive cookies are protected with the httpOnly flag, which mitigates the risk of session hijacking.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
ed10eef1-636d-4fbe-9993-6890dfa878f8
NVD
View on NVD

Affected products (CPE)

ProductCPE
wso2 / api control plane cpe:2.3:a:wso2:api_control_plane:4.5.0:-:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:3.2.1:*:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:4.1.0:-:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:4.2.0:-:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:4.3.0:-:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:4.4.0:-:*:*:*:*:*:*
wso2 / api manager cpe:2.3:a:wso2:api_manager:4.5.0:-:*:*:*:*:*:*
wso2 / enterprise integrator cpe:2.3:a:wso2:enterprise_integrator:6.6.0:*:*:*:*:*:*:*
wso2 / identity server cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*
wso2 / identity server cpe:2.3:a:wso2:identity_server:5.11.0:*:*:*:*:*:*:*
wso2 / identity server cpe:2.3:a:wso2:identity_server:6.0.0:-:*:*:*:*:*:*
wso2 / identity server cpe:2.3:a:wso2:identity_server:6.1.0:-:*:*:*:*:*:*
wso2 / identity server cpe:2.3:a:wso2:identity_server:7.0.0:-:*:*:*:*:*:*
wso2 / identity server cpe:2.3:a:wso2:identity_server:7.1.0:-:*:*:*:*:*:*
wso2 / identity server as key manager cpe:2.3:a:wso2:identity_server_as_key_manager:5.10.0:*:*:*:*:*:*:*
wso2 / open banking am cpe:2.3:a:wso2:open_banking_am:2.0.0:*:*:*:*:*:*:*
wso2 / open banking iam cpe:2.3:a:wso2:open_banking_iam:2.0.0:*:*:*:*:*:*:*
wso2 / traffic manager cpe:2.3:a:wso2:traffic_manager:4.5.0:*:*:*:*:*:*:*
wso2 / universal gateway cpe:2.3:a:wso2:universal_gateway:4.5.0:*:*:*:*:*:*:*

References