CSRF Vulnerability in WSO2 Carbon Server by WSO2
CVE-2016-4315

5.7MEDIUM

Key Information:

Vendor

Wso2

Status
Vendor
CVE Published:
17 February 2017

What is CVE-2016-4315?

A CSRF vulnerability exists in WSO2 Carbon 4.4.5 that enables remote attackers to execute unauthorized actions on behalf of authenticated users. This could lead to the shutdown of server services without user consent. By exploiting this vulnerability, an attacker can manipulate privileged users into inadvertently submitting requests that perform sensitive operations, thereby compromising the integrity and availability of the server.

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.