Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cp5v-2hmc-3vjx

Опубликовано: 02 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site.

By exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.

Пакеты

Наименование

org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 7.0.111

7.0.111

Наименование

org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util

maven
Затронутые версииВерсия исправления

< 5.25.707

5.25.707

EPSS

Процентиль: 13%
0.00043
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 5.4
nvd
8 месяцев назад

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site. By exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.

EPSS

Процентиль: 13%
0.00043
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-601