An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper validation of user-supplied input during API document upload in the Publisher portal. A user with publisher privileges can upload a crafted API document containing malicious JavaScript, which is later rendered in the browser when accessed by other users.

A successful attack could result in redirection to malicious websites, unauthorized UI modifications, or exfiltration of browser-accessible data. However, session-related sensitive cookies are protected by the httpOnly flag, preventing session hijacking.

Project Subscriptions

Vendors Products
Api Control Plane Subscribe
Api Manager Subscribe
Carbon Api Management Api Subscribe
Traffic Manager Subscribe
Universal Gateway Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2025-30893 WSO2 carbon-apimgt affected by an authenticated stored cross-site scripting (XSS) vulnerability
Github GHSA Github GHSA GHSA-cmjc-qp7j-xgwr WSO2 carbon-apimgt affected by an authenticated stored cross-site scripting (XSS) vulnerability
Fixes

Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4104/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4104/#solution


Workaround

No workaround given by the vendor.

History

Fri, 21 Nov 2025 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:wso2:api_control_plane:4.5.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.1.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.2.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.3.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.4.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.5.0:-:*:*:*:*:*:*
cpe:2.3:a:wso2:traffic_manager:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:universal_gateway:4.5.0:*:*:*:*:*:*:*

Thu, 25 Sep 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Wso2
Wso2 api Control Plane
Wso2 api Manager
Wso2 carbon Api Management Api
Wso2 traffic Manager
Wso2 universal Gateway
Vendors & Products Wso2
Wso2 api Control Plane
Wso2 api Manager
Wso2 carbon Api Management Api
Wso2 traffic Manager
Wso2 universal Gateway

Tue, 23 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 23 Sep 2025 15:00:00 +0000

Type Values Removed Values Added
Description An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper validation of user-supplied input during API document upload in the Publisher portal. A user with publisher privileges can upload a crafted API document containing malicious JavaScript, which is later rendered in the browser when accessed by other users. A successful attack could result in redirection to malicious websites, unauthorized UI modifications, or exfiltration of browser-accessible data. However, session-related sensitive cookies are protected by the httpOnly flag, preventing session hijacking.
Title Authenticated Stored Cross-Site Scripting (XSS) in Multiple WSO2 Products via API Document Upload in Publisher
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2025-09-23T19:58:26.062Z

Reserved: 2025-05-15T10:20:31.569Z

Link: CVE-2025-4760

cve-icon Vulnrichment

Updated: 2025-09-23T19:58:23.129Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-23T15:15:31.063

Modified: 2025-11-21T21:29:56.007

Link: CVE-2025-4760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-25T08:22:18Z

Weaknesses