Cross-Site Request Forgery in WSO2 Products
CVE-2025-6670
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 18 November 2025
What is CVE-2025-6670?
Multiple WSO2 products are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability due to improper handling of HTTP GET requests within admin services. This flaw allows attackers to exploit authenticated sessions by tricking users into clicking on malicious links, which can trigger unintended state changes. Although WSO2 implements the SameSite=Lax cookie attribute as a measure, it is not fully effective in preventing exploitation through cross-origin navigation. Unsecured exposure of Carbon console services to the internet can further increase the risk of unauthorized actions, such as data changes and administrative tasks.
Affected Version(s)
org.wso2.carbon:org.wso2.carbon.ui 4.5.3 < 4.5.3.50
org.wso2.carbon:org.wso2.carbon.ui 4.6.0 < 4.6.0.2253
org.wso2.carbon:org.wso2.carbon.ui 4.6.1 < 4.6.1.157
