CVE-2025-5350 describes Server-Side Request Forgery (SSRF) and Reflected Cross-Site Scripting (XSS) vulnerabilities in the deprecated "Try-It" feature of multiple WSO2 products, including API Manager and Identity Server. These flaws, accessible only to administrative users, allow an attacker to craft a malicious link that, when clicked by an administrator, forces the server to fetch and reflect arbitrary content, enabling JavaScript execution for UI manipulation or data exfiltration. Rated Medium severity (CVSS 4.8), the attack requires high privileges and user interaction, but could lead to internal network enumeration via SSRF. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant media coverage, though it has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.5.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_control_plane:4.5.0:-:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:* | ||
3.2.1CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:3.2.1:*:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.