peter bassill · operator
$ cve CVE-2016-4311 JSON

CVE-2016-4311 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 3.4% (pctl 88)

Patch early

A public exploit exists.

Description

Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS3.38% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2017-02-17
Last modified2026-06-17

Affected (1)

VendorProduct
wso2identity server

Public exploits

SourceTitleDate
exploit-dbWSO2 Identity Server 5.1.0 - Multiple Vulnerabilities2016-08-16

References

→ the Explorer  ·  watch your stack  ·  NVD