CSRF Vulnerability in WSO2 Enterprise Integrator Management Console
CVE-2024-0392
What is CVE-2024-0392?
A Cross-Site Request Forgery vulnerability has been identified in the WSO2 Enterprise Integrator 6.6.0 management console. This vulnerability arises from a lack of CSRF token validation, allowing attackers to send deceitful requests that can initiate state-altering actions on behalf of an authenticated user. Successful exploitation of this flaw necessitates social engineering to convince a user with access to the management console to perform the nefarious action. The impact of this vulnerability is limited to a specific range of state-changing operations, which may threaten account settings and overall data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WSO2 Enterprise Integrator 6.6.0 < 6.6.0.179
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
