Reflected Cross-Site Scripting Vulnerability in WSO2 Products
CVE-2025-10853
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 5 November 2025
What is CVE-2025-10853?
A reflected cross-site scripting (XSS) vulnerability affects the management console of multiple WSO2 products due to insufficient output encoding. Attackers can manipulate specific parameters, which allows them to inject arbitrary JavaScript into the responses. This could potentially lead to unauthorized UI manipulation, redirection to harmful websites, or theft of sensitive data from the user's browser. While session cookies are safeguarded with the httpOnly flag to mitigate session hijacking risks, it is crucial for organizations to implement necessary security measures to defend against this type of attack.
Affected Version(s)
org.wso2.carbon.governance:org.wso2.carbon.governance.wsdltool.ui 4.8.19 < 4.8.19.5
org.wso2.carbon.governance:org.wso2.carbon.governance.wsdltool.ui 4.8.21 < 4.8.21.9
org.wso2.carbon.governance:org.wso2.carbon.governance.wsdltool.ui 4.8.28 < 4.8.28.3
