๐Ÿ” CVE Alert

CVE-2024-10302

MEDIUM 4.0

Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure

CVSS Score
4.0
EPSS Score
0.0%
EPSS Percentile
0th

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidated input into user claims can lead to various security risks. Malicious or malformed data injected during signup could be processed by other parts of the application, potentially enabling attacks such as content manipulation, redirection, user interface inconsistencies, unauthorized actions, and data exposure. The actual impact depends on how the compromised data is consumed and the privileges associated with the affected users.

CWE CWE-20
Vendor wso2
Product wso2 api control plane
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for wso2 wso2 api control plane

Be the first to know when new medium vulnerabilities affecting wso2 wso2 api control plane are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

WSO2 / WSO2 API Control Plane
4.5.0 < 4.5.0.10
WSO2 / WSO2 Traffic Manager
4.5.0 < 4.5.0.9
WSO2 / WSO2 Universal Gateway
4.5.0 < 4.5.0.9
WSO2 / WSO2 API Manager
3.1.0 < 3.1.0.331 3.2.0 < 3.2.0.427 3.2.1 < 3.2.1.39 4.0.0 < 4.0.0.318 4.1.0 < 4.1.0.200 4.2.0 < 4.2.0.138 4.3.0 < 4.3.0.51 4.5.0 < 4.5.0.9
WSO2 / WSO2 Open Banking IAM
2.0.0 < 2.0.0.400
WSO2 / WSO2 Identity Server as Key Manager
5.10.0 < 5.10.0.351
WSO2 / WSO2 Identity Server
5.10.0 < 5.10.0.358 5.11.0 < 5.11.0.379
WSO2 / WSO2 Carbon Identity Recovery Management
1.4.1 < 1.4.1.72 1.4.72 < 1.4.72.68 1.4.100 < 1.4.100.8 1.4.102 < 1.4.102.2 1.7.2 < 1.7.2.4 1.8.107 < 1.8.107.2 1.8.108 < 1.8.108.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
security.docs.wso2.com: https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3740/