Loading
Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated and unauthenticated requests.
Use CWE-79, Wso2 vendor hub and Api Manager product page to widen CVE-2023-6838 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-9312, CVE-2025-13590 and CVE-2025-6670 for nearby disclosures in the same product family.