Reflected XSS Vulnerability in WSO2 Identity Server
CVE-2024-7103
4.6MEDIUM
What is CVE-2024-7103?
A reflected cross-site scripting (XSS) vulnerability is present in the login flow of WSO2 Identity Server 7.0.0 due to inadequate input validation. This flaw enables malicious users to inject arbitrary JavaScript into the login process, which could result in alterations to the user interface, redirection to harmful sites, or unauthorized data access from the browser. Although this vulnerability poses significant risks, session-related sensitive cookies are safeguarded with the httpOnly flag, which mitigates the threat of session hijacking.
Affected Version(s)
WSO2 Identity Server 7.0.0 < 7.0.0.64