CVE-2025-6024
Estado: AnalizadaMedia (6.1)—
The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can leverage this by injecting malicious scripts into the authentication endpoint. This can result in the user's browser being redirected to a malicious website, manipulation of the web page's user interface, or the retrieval of information from the browser. However, session hijacking is not possible due to the httpOnly flag protecting session-related cookies.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 13
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-6024",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-6024",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-04-16T12:19:54.071212Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"affectedData": [
{
"vendor": "WSO2",
"product": "WSO2 API Manager",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "3.1.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.1.0",
"lessThan": "3.1.0.351",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.2.0",
"lessThan": "3.2.0.455",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.2.1",
"lessThan": "3.2.1.74",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.0.0",
"lessThan": "4.0.0.375",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.1.0",
"lessThan": "4.1.0.238",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 Identity Server",
"versions": [
{
"status": "unknown",
"version": "0",
"lessThan": "5.10.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.10.0",
"lessThan": "5.10.0.360",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.11.0",
"lessThan": "5.11.0.405",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-04-16T10:16:14.243",
"references": [
{
"url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4251/",
"tags": [
"Vendor Advisory"
],
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection.\nAn attacker can leverage this by injecting malicious scripts into the authentication endpoint. This can result in the user's browser being redirected to a malicious website, manipulation of the web page's user interface, or the retrieval of information from the browser. However, session hijacking is not possible due to the httpOnly flag protecting session-related cookies."
}
],
"lastModified": "2026-06-17T10:01:01.053",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1344FB79-0796-445C-A8F3-C03E995925D1"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E31E32CD-497E-4EF5-B3FC-8718EE06EDAD"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:3.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B58251E8-606B-47C8-8E50-9F9FC8C179BD"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E21D7ABF-C328-425D-B914-618C7628220B"
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:4.1.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51465410-6B7C-40FD-A1AB-A14F650A6AC8"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F4F126CA-A2F9-44F4-968B-DF71765869E5"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:5.11.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2153AECE-020A-4C01-B2A6-F9F5D98E7EBE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}