A vulnerability was discovered on WSO2 products inline API documentation editor page of the API Publisher. A reflected cross-site script (XSS) vulnerability allows an attacker to perform in the inline API documentation editor page of the API Publisher by sending an HTTP GET request with a harmful request parameter for ‘docName.’
Reproduced in a sandboxed environment. Requires only LAN or WiFi adjacency.
The POST request docName variable is vulnerable to reflected Cross-Site Scripting (XSS) in the URL,
Post-exploitation outcomes mapped to CVSS impact metrics.
A runbook, not a checklist. Sequence matters — assume compromise before you act.
Download the relevant patch based on the product version.
Reconstructed from vendor advisories, CISA bulletins, and Securin research records.
Timeline recorded · Disclosure coordinated by Securin
Primary sources — NVD, CISA KEV, and machine-readable IoC feed.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
