CVE-2024-5848
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-5848 is a reflected cross-site scripting (XSS) vulnerability affecting multiple WSO2 products. This issue stems from insufficient input validation, allowing user-supplied data to be directly incorporated into server responses without encoding or sanitization. An attacker can exploit this vulnerability by injecting malicious JavaScript, potentially leading to UI manipulation, redirection to harmful websites, or data exfiltration from the browser. Despite session-related cookies being protected by the httpOnly flag, the severity of the impact depends on the specific service endpoint restrictions in place.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.