CVE-2025-10503Medium· 6.1▾ SunlitThe authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious JavaScript payloads, enabling reflected cr…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious JavaScript payloads, enabling reflected cross-site scripting.
An attacker can leverage this vulnerability to redirect the user's browser to a malicious website, modify the user interface of the web page, retrieve information from the browser, or cause other harmful actions. However, due to the protection of session-related cookies with the httpOnly flag, session hijacking is not possible.
identity_server >= 7.1.0, < 7.1.0.28Upgrade past the affected range:
identity_server 7.1.0.28Connected by shared product, vendor, weakness, or advisory.
CVE-2025-12624Medium· 6.0Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server
CVE-2025-8591Medium· 6.1The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser
CVE-2025-14779Low· 3.8The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type
CVE-2025-13909Medium· 4.3The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators
CVE-2025-11850Medium· 4.3When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary user store and bypasses the primary user store during search and uniqueness checks
CVE-2025-12627Low· 2.4The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions