In accountrecoveryendpoint/ in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter. Once the username or password reset procedure is completed, the JavaScript code will be executed. ( also has an open redirect issue for a similar reason.)

Updated: 2024-08-04T01:01:59.826Z

Reserved: 2021-07-16T00:00:00

CVE-2021-36760

Status : Modified

Published: 2021-12-07T21:15:08.297

Modified: 2024-11-21T06:14:02.127

CVE-2021-36760

