CVE-2025-5350: SSRF and Reflected XSS Vulnerability in Deprecated Try-It Feature of Multiple WSO2 Products
SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepted user-supplied URLs without proper validation, leading to server-side request forgery (SSRF). Additionally, the retrieved content was directly reflected in the HTTP response, enabling reflected cross-site scripting (XSS) in the admin user's browser context.
By tricking an administrator into accessing a crafted link, an attacker could force the server to fetch malicious content and reflect it into the admin’s browser, leading to arbitrary JavaScript execution for UI manipulation or data exfiltration. While session cookies are protected with the HttpOnly flag, the XSS still poses a significant security risk.
Furthermore, SSRF can be used by a privileged user to query internal services, potentially aiding in internal network enumeration if the target endpoints are reachable from the affected product.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5350?
CVE-2025-5350 is classified as a high severity vulnerability due to its potential for server-side request forgery and reflected XSS attacks.
How do I fix CVE-2025-5350?
To mitigate CVE-2025-5350, it is recommended to remove or disable the deprecated Try-It feature in affected WSO2 products.
What products are affected by CVE-2025-5350?
CVE-2025-5350 affects multiple WSO2 products that include the deprecated Try-It feature accessible to administrative users.
What types of attacks are associated with CVE-2025-5350?
CVE-2025-5350 enables server-side request forgery (SSRF) and reflected cross-site scripting (XSS) attacks due to inadequate URL validation.
Who is primarily at risk from CVE-2025-5350?
Administrative users of WSO2 products are primarily at risk from CVE-2025-5350 due to their access to the vulnerable Try-It feature.