Логотип exploitDog
bind:CVE-2025-25967
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-25967

Количество 2

Количество 2

nvd логотип

CVE-2025-25967

11 месяцев назад

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-6pg6-qhjj-4wcm

11 месяцев назад

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-25967

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.

CVSS3: 8.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-6pg6-qhjj-4wcm

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.

CVSS3: 6.8
0%
Низкий
11 месяцев назад

Уязвимостей на страницу