Description

The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to inject malicious script payloads into the input parameters, which are then executed by the victim's browser. Successful exploitation can enable an attacker to redirect the user's browser to a malicious website, modify the UI of the web page, or retrieve information from the browser. However, the impact is limited as session-related sensitive cookies are protected by the httpOnly flag, preventing session hijacking.

INFO

Published Date :

2026-04-16T09:45:46.115Z

Last Modified :

2026-04-16T12:30:30.619Z

Source :

WSO2
AFFECTED PRODUCTS

The following products are affected by CVE-2024-10242 vulnerability.

Vendors Products
Wso2
  • Wso2 Api Manager
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-10242.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact