Cross-Site Scripting Vulnerability in WSO2 API Manager Developer Portal
CVE-2024-4867

5.4MEDIUM

Key Information:

Vendor

Wso2

Vendor
CVE Published:
16 April 2026

What is CVE-2024-4867?

The WSO2 API Manager Developer Portal has a vulnerability that stems from inadequate validation of user-supplied input. This weakness allows an attacker to inject malicious scripts that execute in the user's web browser. Exploitation of this cross-site scripting vulnerability could enable attackers to manipulate the user interface, redirect users to malicious sites, or extract information from the browser. Fortunately, session hijacking is mitigated due to the protection of sensitive cookies with the httpOnly flag, safeguarding user sessions against theft.

Affected Version(s)

WSO2 API Manager 3.2.0 < 3.2.0.408

WSO2 API Manager 3.2.1 < 3.2.1.32

WSO2 API Manager 4.0.0 < 4.0.0.293

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.