Arbitrary File Upload Vulnerability in WSO2 Products
CVE-2025-1862

6.7MEDIUM

What is CVE-2025-1862?

A vulnerability has been identified in multiple WSO2 products that stems from inadequate validation of user-supplied filenames within the BPEL uploader SOAP service endpoint. This flaw allows an attacker with administrative permissions to upload arbitrary files to a user-controlled directory on the server. By exploiting this vulnerability, a malicious user could upload a specially crafted payload, which may lead to remote code execution (RCE). If successfully executed, this could result in full system compromise and unauthorized access to sensitive data.

Affected Version(s)

WSO2 Enterprise Integrator 6.6.0 < 6.6.0.215

WSO2 Identity Server 5.10.0 < 5.10.0.347

WSO2 Identity Server 5.11.0 < 5.11.0.396

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luk Luk
.