Description

A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due to improper output encoding. A malicious actor can exploit this vulnerability by injecting a crafted payload that is reflected in the server response, enabling the execution of arbitrary JavaScript in the victim's browser. This vulnerability could allow attackers to redirect users to malicious websites, modify the user interface, or exfiltrate data from the browser. However, session-related sensitive cookies are protected using the httpOnly flag, which mitigates the risk of session hijacking.

INFO

Published Date :

2025-09-23T17:13:10.597Z

Last Modified :

2025-09-23T18:37:43.867Z

Source :

WSO2
AFFECTED PRODUCTS

The following products are affected by CVE-2025-0209 vulnerability.

Vendors Products
Wso2
  • Identity Server
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-0209.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact