
🚨*CVE* CVE-2025-12627 The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obt… https://www.cve.org/CVERecord?id=CVE-2025-12627 ----- Traducción: CVE-2025-12627 El … http://infoflow.cloud`
Post summary
The post discloses a flaw in WSO2 Identity Server’s user impersonation flow that mismanages refresh tokens, potentially allowing attackers to exploit impersonated sessions.

