PT-2025-8918 · Wso2 · Wso2 Enterprise Integrator
Published
2025-02-27
·
Updated
2025-10-06
·
CVE-2024-0392
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WSO2 Enterprise Integrator version 6.6.0
Description
A Cross-Site Request Forgery (CSRF) issue exists in the management console due to the absence of CSRF token validation. This allows attackers to craft malicious requests that can trigger state-changing operations on behalf of an authenticated user, potentially compromising account settings and data integrity. The issue only affects a limited set of state-changing operations, and successful exploitation requires social engineering to trick a user with access to the management console into performing the malicious action.
Recommendations
For WSO2 Enterprise Integrator version 6.6.0, consider implementing CSRF token validation in the management console to prevent malicious requests. As a temporary workaround, restrict access to the management console and educate users about the risks of social engineering attacks to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wso2 Enterprise Integrator