Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-11438

Опубликовано: 08 окт. 2025
Источник: nvd
CVSS3: 6.3
CVSS2: 6.5
EPSS Низкий

Описание

A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component API Endpoint. Such manipulation leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is beb153ce52dceb971c1518f98333328c95f1ba20. It is best practice to apply a patch to resolve this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jhumanj:opnform:*:*:*:*:*:*:*:*
Версия до 1.9.3 (включая)

EPSS

Процентиль: 14%
0.00046
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.3
github
4 месяца назад

A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component API Endpoint. Such manipulation leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is beb153ce52dceb971c1518f98333328c95f1ba20. It is best practice to apply a patch to resolve this issue.

EPSS

Процентиль: 14%
0.00046
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-862