CVE Feed

    Dashboard / CVE / CVE-2024-3509

    CVE-2024-3509

    A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor within the registry section. To exploit this vulnerability, a malicious actor must have a valid user account with administrative access to the Management Console. If successful, the actor could inject persistent JavaScript payloads, enabling the theft of user data or execution of unauthorized actions on behalf of other users. While this issue enables persistent client-side script execution, session-related cookies remain protected with the httpOnly flag, preventing session hijacking.

    Published:Jun 2, 2025
    Last Modified:Oct 6, 2025
    EPS:Jun 2, 2025
    EPSS Score:0.00044
    CVSS Score:4.3

    Affected Products

    Vendor
    Wso2
    Product
    Api Manager
    Vendor
    Wso2
    Product
    Enterprise Integrator
    Vendor
    Wso2
    Product
    Identity Server
    Vendor
    Wso2
    Product
    Identity Server As Key Manager

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High