CVE Database
/

CVE-2025-6670

Back to search

CVE-2025-6670

Published: Nov 18, 2025

Modified: Nov 18, 2025

PUBLISHED

CVSS v3.1

8.8

HIGH

Description

A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specifically in the event processor of the Carbon console. Although the SameSite=Lax cookie attribute is used as a mitigation, it is ineffective in this context because it allows cookies to be sent with cross-origin top-level navigations using GET requests. A malicious actor can exploit this vulnerability by tricking an authenticated user into visiting a crafted link, leading the browser to issue unintended state-changing requests. Successful exploitation could result in unauthorized operations such as data modification, account changes, or other administrative actions. According to WSO2 Secure Production Guidelines, exposure of Carbon console services to untrusted networks is discouraged, which may reduce the impact in properly secured deployments.

VendorProductVersions

WSO2

WSO2 Open Banking AM

unknown
0 - < 2.0.0
unaffected
2.0.0 - < 2.0.0.398

WSO2

WSO2 Open Banking IAM

unknown
0 - < 2.0.0
unaffected
2.0.0 - < 2.0.0.418

WSO2

WSO2 Traffic Manager

affected
4.5.0 - < 4.5.0.34
affected
4.6.0 - < 4.6.0.1

WSO2

WSO2 Universal Gateway

affected
4.5.0 - < 4.5.0.34
affected
4.6.0 - < 4.6.0.1

WSO2

WSO2 API Control Plane

affected
4.5.0 - < 4.5.0.36
affected
4.6.0 - < 4.6.0.1

WSO2

WSO2 API Manager

unknown
0 - < 3.1.0
affected
3.1.0 - < 3.1.0.349
affected
3.2.0 - < 3.2.0.453
affected
3.2.1 - < 3.2.1.73
affected
4.0.0 - < 4.0.0.373

+6 more versions

WSO2

WSO2 Identity Server

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.378
affected
5.11.0 - < 5.11.0.425
affected
6.0.0 - < 6.0.0.252
affected
6.1.0 - < 6.1.0.253

+3 more versions

WSO2

WSO2 Identity Server as Key Manager

unknown
0 - < 5.10.0
affected
5.10.0 - < 5.10.0.369

WSO2

WSO2 Enterprise Integrator

unknown
0 - < 6.6.0
affected
6.6.0 - < 6.6.0.226

WSO2

org.wso2.carbon:org.wso2.carbon.ui

affected
4.5.3 - < 4.5.3.50
affected
4.6.0 - < 4.6.0.2253
affected
4.6.1 - < 4.6.1.157
affected
4.6.2 - < 4.6.2.673
affected
4.6.3 - < 4.6.3.41

+13 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now