CSRF Vulnerability in WSO2 Enterprise Integrator Management Console
CVE-2024-0392
5.4MEDIUM
Summary
A Cross-Site Request Forgery vulnerability has been identified in the WSO2 Enterprise Integrator 6.6.0 management console. This vulnerability arises from a lack of CSRF token validation, allowing attackers to send deceitful requests that can initiate state-altering actions on behalf of an authenticated user. Successful exploitation of this flaw necessitates social engineering to convince a user with access to the management console to perform the nefarious action. The impact of this vulnerability is limited to a specific range of state-changing operations, which may threaten account settings and overall data integrity.
Affected Version(s)
WSO2 Enterprise Integrator 6.6.0 < 6.6.0.179
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Toqa Hassib - Cyber Security Consultant at Inovasys