CVE-2024-0392

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 27, 2025
CWE ID 352

Summary

CVE-2024-0392 is a newly disclosed Cross-Site Request Forgery (CSRF) vulnerability affecting the management console of WSO2 Enterprise Integrator 6.6.0. This issue stems from the lack of CSRF token validation, making it possible for attackers to craft malicious requests that can induce state-changing operations on behalf of an authenticated user. If successfully exploited, this vulnerability could lead to compromised account settings and potentially compromised data integrity. The CSRF flaw only affects a select group of state-changing operations, and its exploitation requires attackers to trick users with access to the management console into performing the malicious action.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • WSO2 Enterprise Integrator

Affected Vendors

  • WSO2 Inc.