Content Spoofing Vulnerability in WSO2 Products
CVE-2024-6429
4.3MEDIUM
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 23 September 2025
What is CVE-2024-6429?
A content spoofing vulnerability exists in various WSO2 products stemming from improper handling of error messages. In certain scenarios, error messages can be manipulated through URL parameters without adequate validation. This flaw allows malicious actors to inject arbitrary content into the user interface. By exploiting this vulnerability, attackers can alter the error messages displayed in browsers, facilitating social engineering attacks aimed at misleading users with deceptive or harmful information.
Affected Version(s)
WSO2 API Manager 3.2.0 < 3.2.0.409
WSO2 API Manager 3.2.1 < 3.2.1.33
WSO2 API Manager 4.0.0 < 4.0.0.327