CVE-2025-5350Disclosure(wso2 / api_control_plane)

LOWCVSS 4.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepted user-supplied URLs without proper validation, leading to server-side request forgery (SSRF). Additionally, the retrieved content was directly reflected in the HTTP response, enabling reflected cross-site scripting (XSS) in the admin user's browser context. By tricking an administrator into accessing a crafted link, an attacker could force the server to fetch malicious content and reflect it into the admin’s browser, leading to arbitrary JavaScript execution for UI manipulation or data exfiltration. While session cookies are protected with the HttpOnly flag, the XSS still poses a significant security risk. Furthermore, SSRF can be used by a privileged user to query internal services, potentially aiding in internal network enumeration if the target endpoints are reachable from the affected product.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • api_control_plane
  • api_manager
  • enterprise_integrator
  • identity_server

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
api_control_planeapi_managerenterprise_integratoridentity_serveridentity_server_as_key_manageropen_banking_amopen_banking_iamtraffic_manageruniversal_gateway

17 versions affected across 9 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-13: 1Technical Details · 2026-04-13: 104-13
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-5350 - medium 🚨 WSO2 - Server Side Request Forgery > WSO2 products contain SSRF and reflected XSS vulnerabilities in the deprecated Try-It... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-5350 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2025-5350, indicating SSRF and reflected XSS vulnerabilities in WSO2's Try-It feature, but it does not provide exploitation details, PoC, or mitigation information.

    00030313
    959 followersView on X
CPE platform detail22 entries

22 of 22 entries

PartVendorProductVersionTarget SWTarget HW
Appwso2api_control_plane4.5.0--
Appwso2api_manager3.1.0--
Appwso2api_manager3.2.0--
Appwso2api_manager3.2.1--
Appwso2api_manager4.0.0--
Appwso2api_manager4.1.0--
Appwso2api_manager4.2.0--
Appwso2api_manager4.3.0--
Appwso2api_manager4.4.0--
Appwso2api_manager4.5.0--
Appwso2enterprise_integrator6.6.0--
Appwso2identity_server5.10.0--
Appwso2identity_server5.11.0--
Appwso2identity_server6.0.0--
Appwso2identity_server6.1.0--
Appwso2identity_server7.0.0--
Appwso2identity_server7.1.0--
Appwso2identity_server_as_key_manager5.10.0--
Appwso2open_banking_am2.0.0--
Appwso2open_banking_iam2.0.0--
Appwso2traffic_manager4.5.0--
Appwso2universal_gateway4.5.0--

Explore more