National Cyber Warfare Foundation (NCWF)

CVE-2024-6429


0 user ratings
2024-07-01 00:00:00
milo
CVEs

 - archive -- 

CVE-2024-6429

Date: 2024-07-01

CVE Link

A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain conditions, error messages are passed through URL parameters without validation, allowing malicious actors to inject arbitrary content into the UI.

By exploiting this vulnerability, attackers can manipulate browser-displayed error messages, enabling social engineering attacks through deceptive or misleading content.



References:



Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
CVEs



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.