{"id":"CVE-2025-10503","title":"The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding","summary":"The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious JavaScript payloads, enabling reflected cr…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"wso2","product":"identity_server","affected":["identity_server >= 7.1.0, < 7.1.0.28"],"patched":["identity_server 7.1.0.28"],"published":"2026-04-29","updated":"2026-09-30","sourceUpdated":"2026-09-30T22:10:00.273","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-10503","references":[{"url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4577/","label":"ed10eef1-636d-4fbe-9993-6890dfa878f8"}],"tags":["nvd"],"epss":0.00173,"epssPercentile":0.06044,"ingestedAt":"2026-09-30T22:27:27.772Z","slug":"CVE-2025-10503","body":"## Overview\n\nThe authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious JavaScript payloads, enabling reflected cross-site scripting.\n\nAn attacker can leverage this vulnerability to redirect the user's browser to a malicious website, modify the user interface of the web page, retrieve information from the browser, or cause other harmful actions. However, due to the protection of session-related cookies with the httpOnly flag, session hijacking is not possible.\n\n## Affected\n\n- `identity_server >= 7.1.0, < 7.1.0.28`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `identity_server 7.1.0.28`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}