CVE-2025-8591 - CVE House
Back to Database
Status published Medium CVE-2025-8591

Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification

Vulnerability Description

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-8591

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

WSO2 Identity Server, WSO2 API Manager, WSO2 API Control Plane, WSO2 Traffic Manager, WSO2 Universal Gateway, WSO2 Open Banking AM, WSO2 Identity Server as Key Manager, WSO2 Open Banking IAM
Vulnerable Versions:
0, 5.10.0, 6.0.0, 7.0.0, 7.1.0, 3.1.0, 3.2.0, 3.2.1, 4.0.0, 4.1.0, 4.2.0, 4.3.0, 4.4.0, 4.5.0, 4.6.0, 2.0.0

Timeline

Official Publish: July 6th, 2026
Last Modified: July 6th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)