- Description
- The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious JavaScript payloads, enabling reflected cross-site scripting. An attacker can leverage this vulnerability to redirect the user's browser to a malicious website, modify the user interface of the web page, retrieve information from the browser, or cause other harmful actions. However, due to the protection of session-related cookies with the httpOnly flag, session hijacking is not possible.
- Source
- ed10eef1-636d-4fbe-9993-6890dfa878f8
- NVD status
- Analyzed
- Products
- identity_server
CVSS 3.1
- Type
- Secondary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- ed10eef1-636d-4fbe-9993-6890dfa878f8
- CWE-79
- Hype score
- Not currently trending
⚡ New CVE Alert: CVE-2025-10503 📊 Severity: 6.1 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://t.co/qGDZ2vLlXk #CVE-2025-10503 #CVE #Medium #CyberSecurity #InfoSec https://t.co/vs6P4kAueU
@CVEarity
30 Apr 2026
81 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-10503 The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows fo… https://t.co/2HMJTEcUsz
@CVEnew
29 Apr 2026
158 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-10503 Reflected Cross-Site Scripting in Authentication Endpoint via Improper Input Validation https://t.co/ZmvsJK4RxS
@VulmonFeeds
29 Apr 2026
82 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5AADCF27-06C5-40A6-88A0-2F48F62D78B1",
"versionEndExcluding": "7.1.0.28",
"versionStartIncluding": "7.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]