CVE-2025-8591

MEDIUMCVSS 6.1/10EPSS 0.16%

Last modified

CVE-2025-8591 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. EPSS estimates a 0.16% chance of exploitation in the next 30 days.

Description

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.

Metrics

CVSS 3.1
6.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Probability
0.16%

5.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Wso2Api Control Plane>= 4.5.0, < 4.5.0.44
Wso2Api Control Plane>= 4.6.0, < 4.6.0.8
Wso2Api Manager>= 3.1.0, < 3.1.0.355
Wso2Api Manager>= 3.2.0, < 3.2.0.459
Wso2Api Manager>= 3.2.1, < 3.2.1.78
Wso2Api Manager>= 4.0.0, < 4.0.0.380
Wso2Api Manager>= 4.1.0, < 4.1.0.243
Wso2Api Manager>= 4.2.0, < 4.2.0.183
Wso2Api Manager>= 4.3.0, < 4.3.0.94
Wso2Api Manager>= 4.4.0, < 4.4.0.58
Wso2Api Manager>= 4.5.0, < 4.5.0.43
Wso2Api Manager>= 4.6.0, < 4.6.0.7
Wso2Identity Server>= 5.10.0, < 5.10.0.384
Wso2Identity Server>= 6.0.0, < 6.0.0.255
Wso2Identity Server>= 7.0.0, < 7.0.0.131
Wso2Identity Server>= 7.1.0, < 7.1.0.51
Wso2Identity Server As Key Manager>= 5.10.0, < 5.10.0.375
Wso2Open Banking Am>= 2.0.0, < 2.0.0.404
Wso2Open Banking Iam>= 2.0.0, < 2.0.0.424
Wso2Traffic Manager>= 4.5.0, < 4.5.0.42
Wso2Traffic Manager>= 4.6.0, < 4.6.0.7
Wso2Universal Gateway>= 4.5.0, < 4.5.0.42
Wso2Universal Gateway>= 4.6.0, < 4.6.0.7

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2025-8591?
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.
How severe is CVE-2025-8591?
CVE-2025-8591 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 0.16% probability of exploitation in the next 30 days.
How do I fix CVE-2025-8591?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-8591?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST