Reflected XSS Vulnerability in WSO2 Identity Server
CVE-2024-7103

4.6MEDIUM

Key Information:

Vendor

Wso2

Vendor
CVE Published:
22 May 2025

What is CVE-2024-7103?

A reflected cross-site scripting (XSS) vulnerability is present in the login flow of WSO2 Identity Server 7.0.0 due to inadequate input validation. This flaw enables malicious users to inject arbitrary JavaScript into the login process, which could result in alterations to the user interface, redirection to harmful sites, or unauthorized data access from the browser. Although this vulnerability poses significant risks, session-related sensitive cookies are safeguarded with the httpOnly flag, which mitigates the threat of session hijacking.

Affected Version(s)

WSO2 Identity Server 7.0.0 < 7.0.0.64

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Western Shyna
.
CVE-2024-7103 : Reflected XSS Vulnerability in WSO2 Identity Server