CVE-2025-28355

Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none
Configurations

Configuration 1 (hide)

cpe:2.3:a:personal-management-system:personal_management_system:1.4.65:*:*:*:*:*:*:*

History

20 Jun 2025, 16:19

Type Values Removed Values Added
First Time Personal-management-system personal Management System
Personal-management-system
CPE cpe:2.3:a:personal-management-system:personal_management_system:1.4.65:*:*:*:*:*:*:*
References () https://github.com/Volmarg/personal-management-system - () https://github.com/Volmarg/personal-management-system - Product
References () https://github.com/Volmarg/personal-management-system/issues/149 - () https://github.com/Volmarg/personal-management-system/issues/149 - Issue Tracking
References () https://github.com/abbisQQ/CVE-2025-28355/tree/main - () https://github.com/abbisQQ/CVE-2025-28355/tree/main - Exploit, Third Party Advisory
Summary
  • (es) Volmarg Personal Management System 1.4.65 es vulnerable a Cross-Site Request Forgery (CSRF), lo que permite a los atacantes ejecutar código arbitrario y obtener información confidencial a través del atributo de cookie SameSite cuyo valor predeterminado es ninguno.

18 Apr 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-18 19:15

Updated : 2025-06-20 16:19


NVD link : CVE-2025-28355

Mitre link : CVE-2025-28355

CVE.ORG link : CVE-2025-28355


JSON object : View

Products Affected

personal-management-system

  • personal_management_system
CWE
CWE-352

Cross-Site Request Forgery (CSRF)