CVE-2016-4315: WSO2 Carbon

Medium severity, CVSS 5.7. EPSS: 2.8% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.

Affected products

  • WSO2 Carbon: version 4.4.5 only

Published 2017-02-17. Last modified 2026-06-17.