icon

We found results for “

CVE-2024-1440

Good to know:

icon
icon

Date: June 2, 2025

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site.\n\nBy exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.

Severity Score

Severity Score

Weakness Type (CWE)

URL Redirection to Untrusted Site ('Open Redirect')

CWE-601

Top Fix

icon

Upgrade Version

Upgrade to version org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util:5.25.707;org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util:7.0.111;https://github.com/wso2/carbon-identity-framework.git - v5.25.707;https://github.com/wso2/carbon-identity-framework.git - v7.0.111

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us