GHSA-xpxp-r8hf-wgf6
MODERATECVE-2024-8008A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store connection validation request. A malicious actor can inject a specially crafted payload into the request, causing the browser to execute arbitrary JavaScript in the context of the vulnerable page.
- Affected
- < 7.5.12
- Fixed in
- 7.5.12
- Weakness
- CWE-79
- Published
- 2025-06-02
- Source
- github