CVE-2025-25967

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.
References
Link Resource
https://github.com/padayali-JD/CVE-2025-25967 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ddsn:acora_cms:10.1.1:*:*:*:*:*:*:*

History

06 Mar 2025, 12:21

Type Values Removed Values Added
CPE cpe:2.3:a:ddsn:acora_cms:10.1.1:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 6.8
v2 : unknown
v3 : 8.8
First Time Ddsn
Ddsn acora Cms
References () https://github.com/padayali-JD/CVE-2025-25967 - () https://github.com/padayali-JD/CVE-2025-25967 - Third Party Advisory
Summary
  • (es) La versión 10.1.1 de Acora CMS es vulnerable a Cross-Site Request Forgery (CSRF). Esta falla permite a los atacantes engañar a los usuarios autenticados para que realicen acciones no autorizadas, como la eliminación de cuentas o la creación de usuarios, mediante la incorporación de solicitudes maliciosas en contenido externo. La falta de protección CSRF permite la explotación mediante solicitudes manipuladas.

04 Mar 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
CWE CWE-352

03 Mar 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 19:15

Updated : 2025-03-06 12:21


NVD link : CVE-2025-25967

Mitre link : CVE-2025-25967

CVE.ORG link : CVE-2025-25967


JSON object : View

Products Affected

ddsn

  • acora_cms
CWE
CWE-352

Cross-Site Request Forgery (CSRF)