A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain conditions, error messages are passed through URL parameters without validation, allowing malicious actors to inject arbitrary content into the UI. By exploiting this vulnerability, attackers can manipulate browser-displayed error messages, enabling social engineering attacks through deceptive or misleading content.
History

Thu, 25 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 25 Sep 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Wso2
Wso2 api Manager
Wso2 identity Server
Wso2 identity Server As Key Manager
Vendors & Products Wso2
Wso2 api Manager
Wso2 identity Server
Wso2 identity Server As Key Manager

Tue, 23 Sep 2025 17:00:00 +0000

Type Values Removed Values Added
Description A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain conditions, error messages are passed through URL parameters without validation, allowing malicious actors to inject arbitrary content into the UI. By exploiting this vulnerability, attackers can manipulate browser-displayed error messages, enabling social engineering attacks through deceptive or misleading content.
Title Content Spoofing in Multiple WSO2 Products via Error Message Injection
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published: 2025-09-23T16:37:58.340Z

Updated: 2025-09-25T16:14:02.884Z

Reserved: 2024-07-01T12:48:38.456Z

Link: CVE-2024-6429

cve-icon Vulnrichment

Updated: 2025-09-25T16:13:58.398Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-23T17:15:30.643

Modified: 2025-09-25T17:15:37.290

Link: CVE-2024-6429

cve-icon Redhat

No data.