WSO2 Enterprise Integrator Cross-Site Request Forgery Vulnerability in Management Console

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the management console of WSO2 Enterprise Integrator version 6.6.0. The vulnerability arises from a lack of CSRF token validation, allowing attackers to create malicious requests that can initiate state-changing actions on behalf of an authenticated user. This could lead to unauthorized modifications of account settings and data integrity. The issue is limited to a small number of state-changing operations, and successful exploitation would require social engineering to persuade a user with management console access to execute the harmful action.

Impact

Exploitation of this vulnerability could result in unauthorized state changes within the application, potentially allowing attackers to manipulate account settings and disrupt data integrity.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
6.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.