CVE-2025-13394
Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions
Record summary
CVE-2025-13394 has a selected CVSS score of 5.4 (medium).
Description
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie attribute is employed for mitigation, this mechanism is bypassed as it permits cookies to be sent with cross-origin top-level navigation requests, including GET requests. This allows an attacker to trick an authenticated user's browser into unknowingly executing unintended actions. An attacker can exploit this vulnerability to perform unauthorized state-altering requests on behalf of authenticated users. This could lead to consequences such as data modification, account changes, or other actions that could result in data compromise or loss of user control over their account. However, this attack is only feasible if the Carbon console and related services are exposed to the public internet, which is not recommended according to WSO2's security guidelines.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List
Affected products and versions
Showing 12 of 47| Product | Source | Version range | Status |
|---|---|---|---|
WSO2 API Control PlaneBrowse WSO2 / WSO2 API Control PlaneDefault status: unaffected | CVE List | Before 4.5.0 | unknown |
| 4.5.0 to < 4.5.0.39 | affected | ||
| 4.6.0 to < 4.6.0.3 | affected | ||
WSO2 API ManagerBrowse WSO2 / WSO2 API ManagerDefault status: unaffected | CVE List | Before 3.1.0 | unknown |
| 3.1.0 to < 3.1.0.352 | affected | ||
| 3.2.0 to < 3.2.0.456 | affected | ||
| 3.2.1 to < 3.2.1.75 | affected | ||
| 4.0.0 to < 4.0.0.376 | affected | ||
| 4.1.0 to < 4.1.0.239 | affected | ||
| 4.2.0 to < 4.2.0.179 | affected | ||
| 4.3.0 to < 4.3.0.91 | affected | ||
| 4.4.0 to < 4.4.0.55 | affected | ||
| 4.5.0 to < 4.5.0.38 | affected | ||
| 4.6.0 to < 4.6.0.3 | affected | ||
WSO2 Carbon Command Mediator UIBrowse WSO2 / WSO2 Carbon Command Mediator UIorg.wso2.carbon:org.wso2.carbon.mediator.command.uiDefault status: unknown | CVE List | 4.7.30 to < 4.7.30.53 | affected |
| x to ≤ * | unaffected | ||
WSO2 Carbon Component Andes Event UIBrowse WSO2 / WSO2 Carbon Component Andes Event UIorg.wso2.carbon.messaging:org.wso2.carbon.andes.event.uiDefault status: unknown | CVE List | 3.3.12 to < 3.3.12.3 | affected |
| x to ≤ * | unaffected | ||
WSO2 Carbon Component Andes UI1Browse WSO2 / WSO2 Carbon Component Andes UI1org.wso2.carbon.messaging:org.wso2.carbon.andes.uiDefault status: unknown | CVE List | 3.3.12 to < 3.3.12.3 | affected |
| x to ≤ * | unaffected | ||
WSO2 Carbon Email Verification UIBrowse WSO2 / WSO2 Carbon Email Verification UIorg.wso2.carbon:org.wso2.carbon.email.verification.uiDefault status: unknown | CVE List | 4.7.19 to < 4.7.19.14 | affected |
| x to ≤ * | unaffected | ||
WSO2 Carbon Endpoint Editor UIBrowse WSO2 / WSO2 Carbon Endpoint Editor UIorg.wso2.carbonorg.wso2.carbon.endpoint.uiDefault status: unknown | CVE List | 4.7.30 to < 4.7.30.53 | affected |
| x to ≤ * | unaffected | ||
WSO2 Carbon Event Simulator UIBrowse WSO2 / WSO2 Carbon Event Simulator UIorg.wso2.carbon:org.wso2.carbon.event.simulator.uiDefault status: unknown | CVE List | 2.2.11 to < 2.2.11.1 | affected |
| 2.2.14 to < 2.2.14.11 | affected | ||
| 2.2.14 to < 2.2.14.12 | affected | ||
| 2.2.17 to < 2.2.17.5 | affected | ||
| 2.3.1 to < 2.3.1.4 | affected | ||
| 2.3.5 to < 2.3.5.6 | affected | ||
| x to ≤ * | unaffected | ||
WSO2 Carbon Eventing UIBrowse WSO2 / WSO2 Carbon Eventing UIorg.wso2.carbon.commons:org.wso2.carbon.event.uiDefault status: unknown | CVE List | 4.7.19 to < 4.7.19.13 | affected |
| x to ≤ * | unaffected | ||
WSO2 Carbon Execution Manager UIBrowse WSO2 / WSO2 Carbon Execution Manager UIorg.wso2.carbon.analytics-common:org.wso2.carbon.event.template.manager.uiDefault status: unknown | CVE List | 5.2.24 to < 5.2.24.10 | affected |
| 5.2.26 to < 5.2.26.22 | affected | ||
| 5.2.34 to < 5.2.34.12 | affected | ||
| 5.2.41 to < 5.2.41.7 | affected | ||
| 5.2.57 to < 5.2.57.10 | affected | ||
| 5.3.5 to < 5.3.5.9 | affected | ||
| x to ≤ * | unaffected | ||
WSO2 Carbon GovernanceBrowse WSO2 / WSO2 Carbon Governanceorg.wso2.carbon.governance:org.wso2.carbon.governance.apiDefault status: unknown | CVE List | 4.8.37 to < 4.8.37.4 | affected |
| x to ≤ * | unaffected | ||
WSO2 Carbon Governance Custom Lifecycle Checklist UIBrowse WSO2 / WSO2 Carbon Governance Custom Lifecycle Checklist UIorg.wso2.carbon.governance:org.wso2.carbon.governance.custom.lifecycles.checklist.uiDefault status: unknown | CVE List | 4.8.14 to < 4.8.14.4 | affected |
| 4.8.19 to < 4.8.19.8 | affected | ||
| 4.8.21 to < 4.8.21.10 | affected | ||
| 4.8.28 to < 4.8.28.4 | affected | ||
| 4.8.30 to < 4.8.30.6 | affected | ||
| 4.8.32 to < 4.8.32.4 | affected | ||
| x to ≤ * | unaffected |