vendor:
Ws02Carbon
by:
John Page aka HYP3RLINX
5,7
CVSS
MEDIUM
Cross Site Request Forgery / DOS
352
CWE
Product Name: Ws02Carbon
Affected Version From: v4.4.5
Affected Version To: v4.4.5
Patch Exists: YES
Related CWE: CVE-2016-4315
CPE: 2.3:a:wso2:wso2_carbon:4.4.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
WSO2 Carbon v4.4.5 CSRF DOS
The attack involves tricking a privileged user to initiate a request by clicking a malicious link or visiting an evil webpage to shutdown WSO2 Servers.
Mitigation:
The getSafeText() Function and conditional logic should be checked for inbound CSRF attacks.