CVE-2024-4867 Details
Description
The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to inject script content that is executed within the context of a user's browser. By leveraging this cross-site scripting vulnerability, a malicious actor can cause the browser to redirect to a malicious website, make changes to the UI of the web page, or retrieve information from the browser. However, session hijacking is not possible as all session-related sensitive cookies are protected by the httpOnly flag.
A reflected cross-site scripting vulnerability has been identified in the WSO2 API Manager developer portal. This issue arises because the portal does not properly validate user input or encode output, allowing malicious actors to inject script content that is executed in the context of the user's browser. Exploitation of this vulnerability could lead to redirection to a malicious website, unauthorized changes to the web page's user interface, or retrieval of information from the browser. However, session hijacking is not possible, as sensitive session cookies are protected by the httpOnly flag.
WSO2 API Manager users should update to version 4.1.0 (update level 187), 4.0.0 (update level 293), 3.2.1 (update level 32), or 3.2.0 (update level 408).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3391/ | WSO2 LLC | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| wso2 api manager | >= 3.2.0, < 3.2.0.408 >= 3.2.1, < 3.2.1.32 >= 4.0.0, < 4.0.0.293 >= 4.1.0, < 4.1.0.187 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | WSO2 LLC |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | Initial Analysis | [email protected] |
| Apr 16, 2026 | New CVE Received | WSO2 LLC |