Reflected XSS Vulnerability in WSO2 Identity Server
CVE-2024-7103
What is CVE-2024-7103?
A reflected cross-site scripting (XSS) vulnerability is present in the login flow of WSO2 Identity Server 7.0.0 due to inadequate input validation. This flaw enables malicious users to inject arbitrary JavaScript into the login process, which could result in alterations to the user interface, redirection to harmful sites, or unauthorized data access from the browser. Although this vulnerability poses significant risks, session-related sensitive cookies are safeguarded with the httpOnly flag, which mitigates the threat of session hijacking.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WSO2 Identity Server 7.0.0 < 7.0.0.64
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
