Impact
The web portals of WSO2 API Control Plane and WSO2 API Manager allow external links to be opened in a new browser tab. In certain configurations the originating window retains access to the newly opened page, enabling interaction between the two browser contexts when navigating to external destinations. If a user clicks a malicious external link, after the new tab has opened, potentially redirecting the user to phishing pages, stealing credentials, or executing other unauthorized actions within the trusted site.
Affected Systems
WSO2 API Control Plane and WSO2 API Manager are affected. No specific version range is listed, so all current builds of these products should be considered potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity. The attack requires user interaction—clicking a malicious external link that opens in a new tab—after which the attacker can interact with the original window. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no known exploitation yet, but the subversion of the trusted context remains a real threat. Given the moderate CVSS and the user-interaction requirement, the overall risk is moderate awaiting a fix.
OpenCVE Enrichment