CVE-2025-10503
⚪ Do wiadomości
Brak walidacji w punkcie uwierzytelniania umożliwia wstrzyknięcie złośliwego JavaScriptu.
CVSS
6.1
EPSS
0.2%
Exploit
none
Vendor
wso2
Opis źródłowy (NVD)
The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious JavaScript payloads, enabling reflected cross-site scripting. An attacker can leverage this vulnerability to redirect the user's browser to a malicious website, modify the user interface of the web page, retrieve information from the browser, or cause other harmful actions. However, due to the protection of session-related cookies with the httpOnly flag, session hijacking is not possible.
xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-04-29 09:16:23 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 09:10:00 UTC |
Referencje
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4577/ (ed10eef1-636d-4fbe-9993-6890dfa878f8) [Vendor Advisory]