WSO2 - Server Side Request Forgery
CVE-2025-5350
Verified
Description
WSO2 products contain SSRF and reflected XSS vulnerabilities in the deprecated Try-It feature accessible only to administrative users, caused by improper URL validation and direct content reflection, letting attackers trick admins into executing arbitrary JavaScript and querying internal services.
Severity
Medium
CVSS Score
5.9
Exploit Probability
1%
Affected Product
api_manager
Published Date
February 14, 2026
Template Author
sourabh grover
CVE-2025-5350.yaml
5.9Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
CVE ID:
cve-2025-5350
CWE ID:
cwe-79
Remediation Steps
Remove or secure the deprecated Try-It feature and validate user-supplied URLs properly; update to the latest product versions with fixes.