CVE-2025-10503

⚪ Do wiadomości

Brak walidacji w punkcie uwierzytelniania umożliwia wstrzyknięcie złośliwego JavaScriptu.

CVSS
6.1
EPSS
0.2%
Exploit
none
Vendor
wso2
Opis źródłowy (NVD)

The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious JavaScript payloads, enabling reflected cross-site scripting. An attacker can leverage this vulnerability to redirect the user's browser to a malicious website, modify the user interface of the web page, retrieve information from the browser, or cause other harmful actions. However, due to the protection of session-related cookies with the httpOnly flag, session hijacking is not possible.

xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-04-29 09:16:23 UTC
Ostatnia modyfikacja (NVD)2026-10-07 09:10:00 UTC
Referencje