Логотип exploitDog
bind:CVE-2025-4760
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-4760

Количество 2

Количество 2

nvd логотип

CVE-2025-4760

5 месяцев назад

An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper validation of user-supplied input during API document upload in the Publisher portal. A user with publisher privileges can upload a crafted API document containing malicious JavaScript, which is later rendered in the browser when accessed by other users. A successful attack could result in redirection to malicious websites, unauthorized UI modifications, or exfiltration of browser-accessible data. However, session-related sensitive cookies are protected by the httpOnly flag, preventing session hijacking.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-cmjc-qp7j-xgwr

5 месяцев назад

WSO2 carbon-apimgt affected by an authenticated stored cross-site scripting (XSS) vulnerability

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-4760

An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper validation of user-supplied input during API document upload in the Publisher portal. A user with publisher privileges can upload a crafted API document containing malicious JavaScript, which is later rendered in the browser when accessed by other users. A successful attack could result in redirection to malicious websites, unauthorized UI modifications, or exfiltration of browser-accessible data. However, session-related sensitive cookies are protected by the httpOnly flag, preventing session hijacking.

CVSS3: 4.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-cmjc-qp7j-xgwr

WSO2 carbon-apimgt affected by an authenticated stored cross-site scripting (XSS) vulnerability

CVSS3: 4.8
0%
Низкий
5 месяцев назад

Уязвимостей на страницу