CVE-2016-4311

HIGH

WSO2 Identity Server 5.1.0 - Cross-Site Request Forgery in XACML Flow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-4311. PoCs published by hyp3rlinx.

AI-analyzed exploit summary This exploit demonstrates an XML External Entity (XXE) vulnerability in WSO2 Identity Server v5.1.0, allowing an attacker to exfiltrate system files (e.g., Windows hosts file) to a remote server via a malicious DTD file. The attack can be executed remotely via CSRF if an authenticated user interacts with a crafted form.

Description

Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request.

Exploits (1)

exploitdb WORKING POC VERIFIED
by hyp3rlinx · textwebappsjsp
https://www.exploit-db.com/exploits/40239

This exploit demonstrates an XML External Entity (XXE) vulnerability in WSO2 Identity Server v5.1.0, allowing an attacker to exfiltrate system files (e.g., Windows hosts file) to a remote server via a malicious DTD file. The attack can be executed remotely via CSRF if an authenticated user interacts with a crafted form.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: WSO2 Identity Server v5.1.0
Auth required
Prerequisites: Authenticated user session · Victim interaction (CSRF) · Attacker-controlled server to host DTD and receive exfiltrated data
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40239/
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/539199/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92485
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/138329/WSO2-Identity-Server-5.1.0-XML-Injection.html

Scores

CVSS v3 8.8
EPSS 0.0338
EPSS Percentile 87.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
wso2/identity_server 5.1.0
Published Feb 17, 2017
Tracked Since Feb 18, 2026