CVE-2024-0392
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-0392 is a newly disclosed Cross-Site Request Forgery (CSRF) vulnerability affecting the management console of WSO2 Enterprise Integrator 6.6.0. This issue stems from the lack of CSRF token validation, making it possible for attackers to craft malicious requests that can induce state-changing operations on behalf of an authenticated user. If successfully exploited, this vulnerability could lead to compromised account settings and potentially compromised data integrity. The CSRF flaw only affects a select group of state-changing operations, and its exploitation requires attackers to trick users with access to the management console into performing the malicious action.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- WSO2 Enterprise Integrator
Affected Vendors
- WSO2 Inc.