CVE-2025-5770 Details
Description
A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encoding. A malicious actor can inject arbitrary JavaScript payloads into the authentication endpoint, which are reflected back in the response, enabling browser-based attacks. Exploitation may result in redirection to malicious websites, UI manipulation, or unauthorized data access from the victim’s browser. However, session-related cookies are protected with the httpOnly flag, which mitigates session hijacking via this vector.
A reflected cross-site scripting vulnerability has been identified in the authentication endpoints of multiple WSO2 products. This issue arises from inadequate output encoding, allowing malicious actors to inject arbitrary JavaScript payloads that are reflected back in the response. Exploitation of this vulnerability could lead to browser-based attacks, such as redirection to malicious websites, manipulation of the user interface, or unauthorized access to data from the victim's browser. However, it's important to note that session-related cookies are safeguarded with the httpOnly flag, reducing the risk of session hijacking through this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4270/ | WSO2 LLC | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| wso2 api control plane | 4.5.0 - |
CPE
Remediation
| |
| wso2 api manager | 4.2.0 - 4.3.0 - 4.4.0 - 4.5.0 - |
CPE
Remediation
| |
| wso2 identity server | 6.0.0 - 6.1.0 - 7.0.0 - 7.1.0 - |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | WSO2 LLC |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 13, 2025 | Initial Analysis | [email protected] |
| Nov 5, 2025 | New CVE Received | WSO2 LLC |