CVE-2025-8591

Published Jul 6, 2026

Last updated 14 days ago

Overview

Description
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.
Source
ed10eef1-636d-4fbe-9993-6890dfa878f8
NVD status
Analyzed
Products
api_control_plane, api_manager, identity_server, identity_server_as_key_manager, open_banking_am, open_banking_iam, traffic_manager, universal_gateway

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.1
Impact score
2.7
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

ed10eef1-636d-4fbe-9993-6890dfa878f8
CWE-79

Social media

Hype score
Not currently trending

Configurations