2025-03-09 03:03:50 +00:00

60 lines
2.7 KiB
JSON

{
"id": "CVE-2024-0392",
"sourceIdentifier": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"published": "2025-02-27T07:15:32.243",
"lastModified": "2025-02-27T07:15:32.243",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF token validation. This flaw allows attackers to craft malicious requests that can trigger state-changing operations on behalf of an authenticated user, potentially compromising account settings and data integrity. The vulnerability only affects a limited set of state-changing operations, and successful exploitation requires social engineering to trick a user with access to the management console into performing the malicious action."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de Cross-Site Request Forgery (CSRF) en la consola de administraci\u00f3n de WSO2 Enterprise Integrator 6.6.0 debido a la ausencia de validaci\u00f3n de token CSRF. Este fallo permite a los atacantes crear solicitudes maliciosas que pueden activar operaciones de cambio de estado en nombre de un usuario autenticado, lo que podr\u00eda comprometer la configuraci\u00f3n de la cuenta y la integridad de los datos. La vulnerabilidad solo afecta a un conjunto limitado de operaciones de cambio de estado y, para explotarla con \u00e9xito, se requiere ingenier\u00eda social para enga\u00f1ar a un usuario con acceso a la consola de administraci\u00f3n para que realice la acci\u00f3n maliciosa."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 2.8,
"impactScore": 2.5
}
]
},
"weaknesses": [
{
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"references": [
{
"url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2023-2987/",
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}
]
}