Reflected Cross-Site Scripting Vulnerability in WSO2 Products
CVE-2025-10853

5.2MEDIUM

What is CVE-2025-10853?

A reflected cross-site scripting (XSS) vulnerability affects the management console of multiple WSO2 products due to insufficient output encoding. Attackers can manipulate specific parameters, which allows them to inject arbitrary JavaScript into the responses. This could potentially lead to unauthorized UI manipulation, redirection to harmful websites, or theft of sensitive data from the user's browser. While session cookies are safeguarded with the httpOnly flag to mitigate session hijacking risks, it is crucial for organizations to implement necessary security measures to defend against this type of attack.

Affected Version(s)

org.wso2.carbon.governance:org.wso2.carbon.governance.wsdltool.ui 4.8.19 < 4.8.19.5

org.wso2.carbon.governance:org.wso2.carbon.governance.wsdltool.ui 4.8.21 < 4.8.21.9

org.wso2.carbon.governance:org.wso2.carbon.governance.wsdltool.ui 4.8.28 < 4.8.28.3

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

crnković
.
CVE-2025-10853 : Reflected Cross-Site Scripting Vulnerability in WSO2 Products