Back

MEDIUM

Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification

Published Jul 6, 2026

Description

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application.

By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.

Affected products

Remediation

Vendor solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4343/#solution

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WSO2
Published Jul 6, 2026
Updated Jul 6, 2026
Reserved Aug 5, 2025
CISA Vulnrichment
Updated Jul 6, 2026
NVD
Status Analyzed
Modified Oct 6, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WSO2
Published Jul 6, 2026
Updated Jul 6, 2026
Exploited since n/a
EUVD-2025-210428