Web Application Security Flaw in WSO2 Identity Server and API Manager
CVE-2025-6024
6.1MEDIUM
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 16 April 2026
What is CVE-2025-6024?
A vulnerability within WSO2 Identity Server and API Manager allows for script injection through the authentication endpoint, which fails to properly encode user-supplied input. This security lapse enables attackers to inject malicious scripts that can manipulate the web page interface or redirect users to compromised sites. Additionally, sensitive information may be retrieved from the user's browser, despite session hijacking risks being mitigated by the httpOnly flag on session-related cookies.
Affected Version(s)
WSO2 API Manager 3.1.0 < 3.1.0.351
WSO2 API Manager 3.2.0 < 3.2.0.455
WSO2 API Manager 3.2.1 < 3.2.1.74
