We found results for “”
CVE-2024-1440
Good to know:
Date: June 2, 2025
An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site.\n\nBy exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.
Severity Score
Related Resources (9)
Severity Score
Weakness Type (CWE)
URL Redirection to Untrusted Site ('Open Redirect')
CWE-601Top Fix
Upgrade Version
Upgrade to version org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util:5.25.707;org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util:7.0.111;https://github.com/wso2/carbon-identity-framework.git - v5.25.707;https://github.com/wso2/carbon-identity-framework.git - v7.0.111
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


