CVE-2025-8591

EUVD-2025-210428
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application.

By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 5.84%
Affected Products (NVD)
VendorProductVersion
wso2api_control_plane
4.5.0 ≤
𝑥
< 4.5.0.44
wso2api_control_plane
4.6.0 ≤
𝑥
< 4.6.0.8
wso2api_manager
3.1.0 ≤
𝑥
< 3.1.0.355
wso2api_manager
3.2.0 ≤
𝑥
< 3.2.0.459
wso2api_manager
3.2.1 ≤
𝑥
< 3.2.1.78
wso2api_manager
4.0.0 ≤
𝑥
< 4.0.0.380
wso2api_manager
4.1.0 ≤
𝑥
< 4.1.0.243
wso2api_manager
4.2.0 ≤
𝑥
< 4.2.0.183
wso2api_manager
4.3.0 ≤
𝑥
< 4.3.0.94
wso2api_manager
4.4.0 ≤
𝑥
< 4.4.0.58
wso2api_manager
4.5.0 ≤
𝑥
< 4.5.0.43
wso2api_manager
4.6.0 ≤
𝑥
< 4.6.0.7
wso2identity_server
5.10.0 ≤
𝑥
< 5.10.0.384
wso2identity_server
6.0.0 ≤
𝑥
< 6.0.0.255
wso2identity_server
7.0.0 ≤
𝑥
< 7.0.0.131
wso2identity_server
7.1.0 ≤
𝑥
< 7.1.0.51
wso2identity_server_as_key_manager
5.10.0 ≤
𝑥
< 5.10.0.375
wso2open_banking_am
2.0.0 ≤
𝑥
< 2.0.0.404
wso2open_banking_iam
2.0.0 ≤
𝑥
< 2.0.0.424
wso2traffic_manager
4.5.0 ≤
𝑥
< 4.5.0.42
wso2traffic_manager
4.6.0 ≤
𝑥
< 4.6.0.7
wso2universal_gateway
4.5.0 ≤
𝑥
< 4.5.0.42
wso2universal_gateway
4.6.0 ≤
𝑥
< 4.6.0.7
𝑥
= Vulnerable software versions