CVE-2024-0392
Last modified
CVE-2024-0392 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF token validation. This flaw allows attackers to craft malicious requests that can trigger state-changing operations on behalf of an authenticated user, potentially compromising account settings and data integrity. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF token validation. This flaw allows attackers to craft malicious requests that can trigger state-changing operations on behalf of an authenticated user, potentially compromising account settings and data integrity. The vulnerability only affects a limited set of state-changing operations, and successful exploitation requires social engineering to trick a user with access to the management console into performing the malicious action.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Enterprise Integrator | 6.6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-0392?
How severe is CVE-2024-0392?
How do I fix CVE-2024-0392?
Are you affected by CVE-2024-0392?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
