An attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of the webpage, or retrieve sensitive information from the browser. However, the impact is mitigated for session hijacking as all session-related sensitive cookies are protected by the httpOnly flag.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5059/#solution
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 20 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jul 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of the webpage, or retrieve sensitive information from the browser. However, the impact is mitigated for session hijacking as all session-related sensitive cookies are protected by the httpOnly flag. | |
| Title | Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification | |
| First Time appeared |
Wso2
Wso2 wso2 Api Control Plane Wso2 wso2 Api Manager Wso2 wso2 Identity Server |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wso2
Wso2 wso2 Api Control Plane Wso2 wso2 Api Manager Wso2 wso2 Identity Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WSO2
Published:
Updated: 2026-07-20T13:52:59.977Z
Reserved: 2026-02-13T07:48:55.362Z
Link: CVE-2026-2445
Updated: 2026-07-20T13:52:54.856Z
No data.
No data.
OpenCVE Enrichment
No data.