Record summary

CVE-2025-13394 has a selected CVSS score of 5.4 (medium).

Description

The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie attribute is employed for mitigation, this mechanism is bypassed as it permits cookies to be sent with cross-origin top-level navigation requests, including GET requests. This allows an attacker to trick an authenticated user's browser into unknowingly executing unintended actions. An attacker can exploit this vulnerability to perform unauthorized state-altering requests on behalf of authenticated users. This could lead to consequences such as data modification, account changes, or other actions that could result in data compromise or loss of user control over their account. However, this attack is only feasible if the Carbon console and related services are exposed to the public internet, which is not recommended according to WSO2's security guidelines.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List

Affected products and versions

Showing 12 of 47
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListBefore 4.5.0unknown
4.5.0 to < 4.5.0.39affected
4.6.0 to < 4.6.0.3affected

Default status: unaffected

CVE ListBefore 3.1.0unknown
3.1.0 to < 3.1.0.352affected
3.2.0 to < 3.2.0.456affected
3.2.1 to < 3.2.1.75affected
4.0.0 to < 4.0.0.376affected
4.1.0 to < 4.1.0.239affected
4.2.0 to < 4.2.0.179affected
4.3.0 to < 4.3.0.91affected
4.4.0 to < 4.4.0.55affected
4.5.0 to < 4.5.0.38affected
4.6.0 to < 4.6.0.3affected

WSO2 Carbon Command Mediator UI

Browse WSO2 / WSO2 Carbon Command Mediator UIorg.wso2.carbon:org.wso2.carbon.mediator.command.ui

Default status: unknown

CVE List4.7.30 to < 4.7.30.53affected
x to ≤ *unaffected

WSO2 Carbon Component Andes Event UI

Browse WSO2 / WSO2 Carbon Component Andes Event UIorg.wso2.carbon.messaging:org.wso2.carbon.andes.event.ui

Default status: unknown

CVE List3.3.12 to < 3.3.12.3affected
x to ≤ *unaffected

WSO2 Carbon Component Andes UI1

Browse WSO2 / WSO2 Carbon Component Andes UI1org.wso2.carbon.messaging:org.wso2.carbon.andes.ui

Default status: unknown

CVE List3.3.12 to < 3.3.12.3affected
x to ≤ *unaffected

WSO2 Carbon Email Verification UI

Browse WSO2 / WSO2 Carbon Email Verification UIorg.wso2.carbon:org.wso2.carbon.email.verification.ui

Default status: unknown

CVE List4.7.19 to < 4.7.19.14affected
x to ≤ *unaffected

WSO2 Carbon Endpoint Editor UI

Browse WSO2 / WSO2 Carbon Endpoint Editor UIorg.wso2.carbonorg.wso2.carbon.endpoint.ui

Default status: unknown

CVE List4.7.30 to < 4.7.30.53affected
x to ≤ *unaffected

WSO2 Carbon Event Simulator UI

Browse WSO2 / WSO2 Carbon Event Simulator UIorg.wso2.carbon:org.wso2.carbon.event.simulator.ui

Default status: unknown

CVE List2.2.11 to < 2.2.11.1affected
2.2.14 to < 2.2.14.11affected
2.2.14 to < 2.2.14.12affected
2.2.17 to < 2.2.17.5affected
2.3.1 to < 2.3.1.4affected
2.3.5 to < 2.3.5.6affected
x to ≤ *unaffected

WSO2 Carbon Eventing UI

Browse WSO2 / WSO2 Carbon Eventing UIorg.wso2.carbon.commons:org.wso2.carbon.event.ui

Default status: unknown

CVE List4.7.19 to < 4.7.19.13affected
x to ≤ *unaffected

WSO2 Carbon Execution Manager UI

Browse WSO2 / WSO2 Carbon Execution Manager UIorg.wso2.carbon.analytics-common:org.wso2.carbon.event.template.manager.ui

Default status: unknown

CVE List5.2.24 to < 5.2.24.10affected
5.2.26 to < 5.2.26.22affected
5.2.34 to < 5.2.34.12affected
5.2.41 to < 5.2.41.7affected
5.2.57 to < 5.2.57.10affected
5.3.5 to < 5.3.5.9affected
x to ≤ *unaffected

WSO2 Carbon Governance

Browse WSO2 / WSO2 Carbon Governanceorg.wso2.carbon.governance:org.wso2.carbon.governance.api

Default status: unknown

CVE List4.8.37 to < 4.8.37.4affected
x to ≤ *unaffected

WSO2 Carbon Governance Custom Lifecycle Checklist UI

Browse WSO2 / WSO2 Carbon Governance Custom Lifecycle Checklist UIorg.wso2.carbon.governance:org.wso2.carbon.governance.custom.lifecycles.checklist.ui

Default status: unknown

CVE List4.8.14 to < 4.8.14.4affected
4.8.19 to < 4.8.19.8affected
4.8.21 to < 4.8.21.10affected
4.8.28 to < 4.8.28.4affected
4.8.30 to < 4.8.30.6affected
4.8.32 to < 4.8.32.4affected
x to ≤ *unaffected

References

2