CVE-2025-8591
Last modified
CVE-2025-8591 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Api Control Plane | >= 4.5.0, < 4.5.0.44 |
| Wso2 | Api Control Plane | >= 4.6.0, < 4.6.0.8 |
| Wso2 | Api Manager | >= 3.1.0, < 3.1.0.355 |
| Wso2 | Api Manager | >= 3.2.0, < 3.2.0.459 |
| Wso2 | Api Manager | >= 3.2.1, < 3.2.1.78 |
| Wso2 | Api Manager | >= 4.0.0, < 4.0.0.380 |
| Wso2 | Api Manager | >= 4.1.0, < 4.1.0.243 |
| Wso2 | Api Manager | >= 4.2.0, < 4.2.0.183 |
| Wso2 | Api Manager | >= 4.3.0, < 4.3.0.94 |
| Wso2 | Api Manager | >= 4.4.0, < 4.4.0.58 |
| Wso2 | Api Manager | >= 4.5.0, < 4.5.0.43 |
| Wso2 | Api Manager | >= 4.6.0, < 4.6.0.7 |
| Wso2 | Identity Server | >= 5.10.0, < 5.10.0.384 |
| Wso2 | Identity Server | >= 6.0.0, < 6.0.0.255 |
| Wso2 | Identity Server | >= 7.0.0, < 7.0.0.131 |
| Wso2 | Identity Server | >= 7.1.0, < 7.1.0.51 |
| Wso2 | Identity Server As Key Manager | >= 5.10.0, < 5.10.0.375 |
| Wso2 | Open Banking Am | >= 2.0.0, < 2.0.0.404 |
| Wso2 | Open Banking Iam | >= 2.0.0, < 2.0.0.424 |
| Wso2 | Traffic Manager | >= 4.5.0, < 4.5.0.42 |
| Wso2 | Traffic Manager | >= 4.6.0, < 4.6.0.7 |
| Wso2 | Universal Gateway | >= 4.5.0, < 4.5.0.42 |
| Wso2 | Universal Gateway | >= 4.6.0, < 4.6.0.7 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-8591?
How severe is CVE-2025-8591?
How do I fix CVE-2025-8591?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-8585A vulnerability, which was classified as critical, has been …5.3
- CVE-2025-8586A vulnerability, which was classified as problematic, was fo…3.3
- CVE-2025-8587Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2025-8588The Gutenberg Blocks – PublishPress Blocks plugin for WordPr…6.4
- CVE-2025-8589Improper Neutralization of Input During Web Page Generation …7.6
- CVE-2025-8590Exposure of Sensitive Information to an Unauthorized Actor v…7.5
- CVE-2025-8592The Inspiro theme for WordPress is vulnerable to Cross-Site …8.1
- CVE-2025-8593The GSheetConnector For Gravity Forms plugin for WordPress i…8.8
- CVE-2025-8594The Pz-LinkCard WordPress plugin before 2.5.7 does not valid…3.8
- CVE-2025-8595The Zakra theme for WordPress is vulnerable to unauthorized …4.3
- CVE-2025-8597MacVim's configuration on macOS, specifically the presence o…4.8
- CVE-2025-8603The Unlimited Elements For Elementor plugin for WordPress is…6.4
Are you affected by CVE-2025-8591?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
