User Input Validation Flaw in WSO2 Products
CVE-2024-10302
4MEDIUM
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2024-10302?
A significant input validation flaw exists in multiple WSO2 products during user self-signup processes. This vulnerability permits malicious or improperly formatted data to gain entry into user claims without adequate validation. Consequently, this unvalidated input can lead to various downstream security risks, namely content manipulation, potential redirection attacks, user interface inconsistencies, unauthorized actions, and data exposure. The extent of the impact is contingent on how this compromised data is utilized, as well as the user privileges associated with the affected accounts.
Affected Version(s)
WSO2 API Control Plane 4.5.0 < 4.5.0.10
WSO2 API Manager 3.1.0 < 3.1.0.331
WSO2 API Manager 3.2.0 < 3.2.0.427
