685
VMScore

CVE-2016-4311

Published: 17/02/2017 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote malicious users to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request.

Vulnerable Product Search on Vulmon Subscribe to Product

wso2 identity server 5.1.0

Exploits

[+] Credits: John Page aka HYP3RLINX [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/WSO2-IDENTITY-SERVER-v510-XML-External-Entitytxt [+] ISR: ApparitionSec Vendor: ============= wwwwso2com Product: ============================ Wso2 Identity Server v510 As the industry’s first enterprise ...
WSO2 Identity Server version 510 suffers from cross site request forgery and XML external-entity injection vulnerabilities ...