CVE-2024-4867: WSO2 API Manager
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to inject script content that is executed within the context of a user's browser. By leveraging this cross-site scripting vulnerability, a malicious actor can cause the browser to redirect to a malicious website, make changes to the UI of the web page, or retrieve information from the browser. However, session hijacking is not possible as all session-related sensitive cookies are protected by the httpOnly flag.
Affected products
- WSO2 API Manager: from 3.2.0, before 3.2.0.408 (fixed in 3.2.0.408); from 3.2.1, before 3.2.1.32 (fixed in 3.2.1.32); from 4.0.0, before 4.0.0.293 (fixed in 4.0.0.293); from 4.1.0, before 4.1.0.187 (fixed in 4.1.0.187)
Published 2026-04-16. Last modified 2026-06-17.