/Vulnerability Library

WSO2 - Server Side Request Forgery

CVE-2025-5350
Verified

Description

WSO2 products contain SSRF and reflected XSS vulnerabilities in the deprecated Try-It feature accessible only to administrative users, caused by improper URL validation and direct content reflection, letting attackers trick admins into executing arbitrary JavaScript and querying internal services.

Severity

Medium

CVSS Score

5.9

Exploit Probability

1%

Affected Product

api_manager

Published Date

February 14, 2026

Template Author

sourabh grover

CVE-2025-5350.yaml
5.9Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
CVE ID:
cve-2025-5350
CWE ID:
cwe-79

References

https://crnkovic.dev/wso2-server-side-request-forgery/

Remediation Steps

Remove or secure the deprecated Try-It feature and validate user-supplied URLs properly; update to the latest product versions with fixes.