PT-2021-21342 · Wso2 · Wso2 Identity Server

Published

2021-12-07

·

Updated

2021-12-09

·

CVE-2021-36760

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WSO2 Identity Server version 5.7.0
Description A DOM-Based XSS attack is possible in the account recovery endpoint, affecting the callback parameter by modifying the URL that precedes it. Once the username or password reset procedure is completed, the JavaScript code will be executed. Additionally, there is an open redirect issue in the recoverpassword.do endpoint for a similar reason.
Recommendations For WSO2 Identity Server version 5.7.0, consider disabling the recoverpassword.do endpoint until a patch is available to prevent potential DOM-Based XSS attacks. Restrict access to the accountrecoveryendpoint to minimize the risk of exploitation. Avoid using the callback parameter in the affected endpoint until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36760

Affected Products

Wso2 Identity Server