CVE-2021-36760
In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter.
Does this matter?
Lower severity and a low EPSS score (0.72%). Track it; it rarely justifies an emergency change on its own.
Description
In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter. Once the username or password reset procedure is completed, the JavaScript code will be executed. (recoverpassword.do also has an open redirect issue for a similar reason.)
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.72% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wso2/api manager · wso2/identity server · wso2/identity server as key manager · wso2/iot server
- Source
- cve@mitre.org
References
- https://docs.wso2.com/display/Security/2021+AdvisoriesVendor Advisory
- https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2021-1314Vendor Advisory
- https://docs.wso2.com/display/Security/2021+AdvisoriesVendor Advisory
- https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2021-1314Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.