Impact
Insufficient HTML sanitization in the Publisher Portal and Developer Portal permits untrusted content to be rendered without proper encoding or neutralization, enabling the injection and execution of malicious JavaScript. This cross‑site scripting flaw can allow an attacker to run arbitrary scripts in the context of any user who views the affected API documentation, potentially performing actions on the user’s behalf depending on the session’s privileges.
Affected Systems
The vulnerability affects WSO2 API Control Plane and WSO2 API Manager through their Publisher and Developer Portals. No specific product versions are listed, so all releases using these portals are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score of 0.0018 (< 1%) indicates a very low exploitation probability, and the flaw is not listed in the CISA KEV catalog. Successful exploitation requires a user with permission to access the API documentation where the untrusted input is embedded. Attackers may gain the ability to execute malicious scripts on behalf of that user, potentially leading to data theft, session hijack, or other privilege‑based attacks. While no explicit exploit code is disclosed, the flaw can be triggered through crafted API documentation content.
OpenCVE Enrichment