Cross-Site Request Forgery in WSO2 Products
CVE-2025-6670

8.8HIGH

What is CVE-2025-6670?

Multiple WSO2 products are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability due to improper handling of HTTP GET requests within admin services. This flaw allows attackers to exploit authenticated sessions by tricking users into clicking on malicious links, which can trigger unintended state changes. Although WSO2 implements the SameSite=Lax cookie attribute as a measure, it is not fully effective in preventing exploitation through cross-origin navigation. Unsecured exposure of Carbon console services to the internet can further increase the risk of unauthorized actions, such as data changes and administrative tasks.

Affected Version(s)

org.wso2.carbon:org.wso2.carbon.ui 4.5.3 < 4.5.3.50

org.wso2.carbon:org.wso2.carbon.ui 4.6.0 < 4.6.0.2253

org.wso2.carbon:org.wso2.carbon.ui 4.6.1 < 4.6.1.157

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Noël MACCARY
.
CVE-2025-6670 : Cross-Site Request Forgery in WSO2 Products