Reflected Cross-Site Scripting Vulnerability in WSO2 Authentication Endpoint
CVE-2025-10503

6.1MEDIUM

Key Information:

Vendor

Wso2

Vendor
CVE Published:
29 April 2026

What is CVE-2025-10503?

The vulnerability in the WSO2 authentication endpoint arises from improper validation of user-supplied input, which permits the injection of malicious JavaScript payloads. This could allow attackers to alter the user interface, redirect users to malicious sites, or extract sensitive information from the user's browser. Although the session cookies are secured with the httpOnly flag, preventing session hijacking, users remain vulnerable to other exploits leveraging this XSS flaw.

Affected Version(s)

WSO2 Identity Server 7.1.0 < 7.1.0.28

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.