Content Spoofing Vulnerability in WSO2 Products
CVE-2024-6429
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 23 September 2025
What is CVE-2024-6429?
A content spoofing vulnerability exists in various WSO2 products stemming from improper handling of error messages. In certain scenarios, error messages can be manipulated through URL parameters without adequate validation. This flaw allows malicious actors to inject arbitrary content into the user interface. By exploiting this vulnerability, attackers can alter the error messages displayed in browsers, facilitating social engineering attacks aimed at misleading users with deceptive or harmful information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WSO2 API Manager 3.2.0 < 3.2.0.409
WSO2 API Manager 3.2.1 < 3.2.1.33
WSO2 API Manager 4.0.0 < 4.0.0.327
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
