CVE-2024-0392 Details
Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF token validation. This flaw allows attackers to craft malicious requests that can trigger state-changing operations on behalf of an authenticated user, potentially compromising account settings and data integrity. The vulnerability only affects a limited set of state-changing operations, and successful exploitation requires social engineering to trick a user with access to the management console into performing the malicious action.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the management console of WSO2 Enterprise Integrator version 6.6.0. The vulnerability arises from a lack of CSRF token validation, allowing attackers to create malicious requests that can initiate state-changing actions on behalf of an authenticated user. This could lead to unauthorized modifications of account settings and data integrity. The issue is limited to a small number of state-changing operations, and successful exploitation would require social engineering to persuade a user with management console access to execute the harmful action.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2023-2987/ | WSO2 LLC | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| wso2 enterprise integrator | 6.6.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | WSO2 LLC |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 6, 2025 | Initial Analysis | [email protected] |
| Feb 27, 2025 | New CVE Received | WSO2 LLC |