PT-2021-21342 · Wso2 · Wso2 Identity Server
Published
2021-12-07
·
Updated
2021-12-09
·
CVE-2021-36760
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WSO2 Identity Server version 5.7.0
Description
A DOM-Based XSS attack is possible in the account recovery endpoint, affecting the
callback parameter by modifying the URL that precedes it. Once the username or password reset procedure is completed, the JavaScript code will be executed. Additionally, there is an open redirect issue in the recoverpassword.do endpoint for a similar reason.Recommendations
For WSO2 Identity Server version 5.7.0, consider disabling the
recoverpassword.do endpoint until a patch is available to prevent potential DOM-Based XSS attacks. Restrict access to the accountrecoveryendpoint to minimize the risk of exploitation. Avoid using the callback parameter in the affected endpoint until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wso2 Identity Server