CVE Feed

    Dashboard / CVE / CVE-2024-10242

    CVE-2024-10242

    The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to inject malicious script payloads into the input parameters, which are then executed by the victim's browser. Successful exploitation can enable an attacker to redirect the user's browser to a malicious website, modify the UI of the web page, or retrieve information from the browser. However, the impact is limited as session-related sensitive cookies are protected by the httpOnly flag, preventing session hijacking.

    Published:Apr 16, 2026
    Last Modified:Apr 23, 2026
    EPS:Apr 16, 2026
    EPSS Score:0.00015
    CVSS Score:6.1

    Affected Products

    Vendor
    Wso2
    Product
    Api Manager
    Vendor
    Wso2
    Product
    Wso2 Api Manager

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High