lokvica

Reflected Cross-Site Scripting (3x XSS) in Multiple WSO2 Products

Date:
CVE ID: CVE-2025-10853
CVSS score: 6.1 * (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Product: Multiple (WSO2)
Researcher: @crnkovic
Type: XSS
CWE: CWE-79

Three distinct reflected cross-site scripting vulnerabilities exist in the management console of multiple WSO2 products, grouped under a single CVE. In each case, user-controlled input is reflected into the HTML response without sanitisation. The affected endpoints are:

If a server administrator follows a malicious link, the injected JavaScript executes in the context of the management console session. From there, the attacker can invoke SOAP admin services (CVE-2025-10907) to achieve one-click remote code execution on the underlying server.

This vulnerability was responsibly disclosed and has been patched by the vendor.

Affected products

See also