Reflected Cross-Site Scripting (XSS) in Authentication Endpoints of Multiple WSO2 Products
Vulnerability Description
A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encoding. A malicious actor can inject arbitrary JavaScript payloads into the authentication endpoint, which are reflected back in the response, enabling browser-based attacks. Exploitation may result in redirection to malicious websites, UI manipulation, or unauthorized data access from the victim’s browser. However, session-related cookies are protected with the httpOnly flag, which mitigates session hijacking via this vector.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5770
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- crnković
More from WSO2
View All →Affected Vendor
WSO2
View all reports →