CVE-2024-8008: Reflected Cross-Site Scripting (XSS) in Multiple WSO2 Products via JDBC User Store Connection Validation

Published Jun 2, 2025
·
Updated

A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store connection validation request. A malicious actor can inject a specially crafted payload into the request, causing the browser to execute arbitrary JavaScript in the context of the vulnerable page.

This vulnerability may allow UI manipulation, redirection to malicious websites, or data exfiltration from the browser. However, since all session-related sensitive cookies are protected with the httpOnly flag, session hijacking is not possible.

Affected Software

18 affected componentsFixes available
WSO2 Multiple Products
maven/org.wso2.carbon.identity.framework:org.wso2.carbon.identity.user.store.configuration.ui<7.5.12
7.5.12
WSO2 API Manager=3.1.0
WSO2 API Manager=3.2.0
WSO2 API Manager=3.2.1
WSO2 API Manager=4.0.0
WSO2 API Manager=4.1.0
WSO2 API Manager=4.2.0
WSO2 API Manager=4.3.0
WSO2 Enterprise Integrator=6.6.0
WSO2 Identity Server=5.10.0
WSO2 Identity Server=5.11.0
WSO2 Identity Server=6.0.0
WSO2 Identity Server=6.1.0
WSO2 Identity Server=7.0.0
WSO2 Identity Server as Key Manager=5.10.0
WSO2 Open Banking AM=2.0.0
WSO2 Open Banking Iam=2.0.0

Remediation

Information

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2024-3178/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2024-3178/#solution

Event History

Jun 2, 2025
CVE Published
via MITRE·04:48 PM
Data Sourced
via MITRE·04:48 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
Affected Software
Advisory Published
via GitHub·06:30 PM
Data Sourced
via GitHub·06:30 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-8008?

CVE-2024-8008 has been classified as a reflected cross-site scripting (XSS) vulnerability, which can pose moderate to high risk depending on the context of exploitation.

2

How do I fix CVE-2024-8008?

To mitigate CVE-2024-8008, ensure that output encoding is properly applied to all error messages generated by the JDBC user store connection validation.

3

Which products are affected by CVE-2024-8008?

CVE-2024-8008 affects multiple WSO2 products that utilize the JDBC user store.

4

Can CVE-2024-8008 be exploited remotely?

Yes, CVE-2024-8008 can be exploited remotely by a malicious actor through crafted requests.

5

What impact does CVE-2024-8008 have on users?

CVE-2024-8008 can lead to unauthorized access or data compromise through the execution of arbitrary scripts in users' browsers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203