CVE-2025-12737 | WSO2 API Control Plane Carbon Console injection

SecurityVulns

A vulnerability was found in WSO2 API Control Plane, API Manager, Identity Server, Identity Server as Key Manager, Open Banking AM, Open Banking IAM, Traffic Manager and Universal Gateway and classified as problematic. The impacted element is an unknown function of the component Carbon Console. Executing a manipulation can lead to injection.

This vulnerability is handled as CVE-2025-12737. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More