Server-Side Request Forgery Vulnerability in WSO2 Dashboard Server
CVE-2019-6516

5.8MEDIUM

Key Information:

Vendor

Wso2

Vendor
CVE Published:
14 May 2019

What is CVE-2019-6516?

A vulnerability in WSO2 Dashboard Server version 2.0.0 allows attackers to exploit the server's capabilities to make internal requests. This may include executing unauthorized requests that not only target the internal workstation but can also scan adjacent workstations within the network. Such behavior opens up possibilities for attackers to map out the internal network patterns, which can lead to further exploitation and data breaches.

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.