{"id":"CVE-2025-5770","details":"A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encoding. A malicious actor can inject arbitrary JavaScript payloads into the authentication endpoint, which are reflected back in the response, enabling browser-based attacks.\n\nExploitation may result in redirection to malicious websites, UI manipulation, or unauthorized data access from the victim’s browser. However, session-related cookies are protected with the httpOnly flag, which mitigates session hijacking via this vector.","modified":"2026-07-08T08:12:39.525877906Z","published":"2025-11-05T19:16:01.880Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:wso2:api_control_plane:4.5.0:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.5.0-NA"},{"last_affected":"4.5.0-NA"}],"source":"CPE_STRING","vendor_product":"wso2:api_control_plane"},{"cpes":["cpe:2.3:a:wso2:identity_server:6.0.0:-:*:*:*:*:*:*","cpe:2.3:a:wso2:identity_server:6.1.0:-:*:*:*:*:*:*","cpe:2.3:a:wso2:identity_server:7.0.0:-:*:*:*:*:*:*","cpe:2.3:a:wso2:identity_server:7.1.0:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"6.0.0-NA"},{"last_affected":"6.0.0-NA"},{"introduced":"6.1.0-NA"},{"last_affected":"6.1.0-NA"},{"introduced":"7.0.0-NA"},{"last_affected":"7.0.0-NA"},{"introduced":"7.1.0-NA"},{"last_affected":"7.1.0-NA"}],"source":"CPE_STRING","vendor_product":"wso2:identity_server"}]},"references":[{"type":"ADVISORY","url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4270/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wso2/product-apim","events":[{"introduced":"572610e8e6564a647044bdb454eda658e1253352"},{"last_affected":"f84a64d6683176f3ffb57fa262f3035b69781f2f"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:wso2:api_manager:4.2.0:-:*:*:*:*:*:*","cpe:2.3:a:wso2:api_manager:4.3.0:-:*:*:*:*:*:*","cpe:2.3:a:wso2:api_manager:4.4.0:-:*:*:*:*:*:*","cpe:2.3:a:wso2:api_manager:4.5.0:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.2.0-NA"},{"last_affected":"4.2.0-NA"},{"introduced":"4.3.0-NA"},{"last_affected":"4.3.0-NA"},{"introduced":"4.4.0-NA"},{"last_affected":"4.4.0-NA"},{"introduced":"4.5.0-NA"},{"last_affected":"4.5.0-NA"}]}}],"versions":["4.2.0-NA","4.3.0-NA","4.4.0-NA","4.5.0-NA","v4.5.0-tm-rc2","v4.5.0-tm","v4.5.0-acp-rc2","v4.5.0-acp","v4.5.0-rc","v4.5.0-gw-rc","v4.5.0-tm-rc","v4.5.0-acp-rc","v4.5.0-beta","v4.5.0-gw-beta","v4.5.0-tm-beta","v4.5.0-acp-beta","v4.5.0-acp-alpha","v4.5.0-tm-alpha","v4.5.0-gw-alpha","v4.5.0-m2","v4.5.0-acp-m1","v4.5.0-tm-m1","v4.5.0-gw-m1","v4.5.0-m1","v4.3.0-rc2","v4.3.0","v4.4.0-rc2","v4.4.0","v4.4.0-rc","v4.4.0-beta","v4.4.0-alpha","v4.4.0-m1","v4.3.0-rc","v4.3.0-beta","v4.3.0-alpha2","v4.3.0-alpha","v4.3.0-m2","v4.2.0-rc2","v4.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5770.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}