Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.
References
Link | Resource |
---|---|
https://github.com/padayali-JD/CVE-2025-25967 | Third Party Advisory |
Configurations
History
06 Mar 2025, 12:21
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:ddsn:acora_cms:10.1.1:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
First Time |
Ddsn
Ddsn acora Cms |
|
References | () https://github.com/padayali-JD/CVE-2025-25967 - Third Party Advisory | |
Summary |
|
04 Mar 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
CWE | CWE-352 |
03 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-03 19:15
Updated : 2025-03-06 12:21
NVD link : CVE-2025-25967
Mitre link : CVE-2025-25967
CVE.ORG link : CVE-2025-25967
JSON object : View
Products Affected
ddsn
- acora_cms
CWE
CWE-352
Cross-Site Request Forgery (CSRF)