CVE-2024-5848

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Feb 27, 2025
CWE ID 79

Summary

CVE-2024-5848 is a reflected cross-site scripting (XSS) vulnerability affecting multiple WSO2 products. This issue stems from insufficient input validation, allowing user-supplied data to be directly incorporated into server responses without encoding or sanitization. An attacker can exploit this vulnerability by injecting malicious JavaScript, potentially leading to UI manipulation, redirection to harmful websites, or data exfiltration from the browser. Despite session-related cookies being protected by the httpOnly flag, the severity of the impact depends on the specific service endpoint restrictions in place.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share