CVE-2025-29722

A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:yassmittal:commercify:1.0:*:*:*:*:*:*:*

History

23 Apr 2025, 18:49

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad CSRF en Commercify v1.0 permite a atacantes remotos realizar acciones no autorizadas en nombre de usuarios autenticados. El problema se debe a la falta de protección CSRF en endpoints sensibles.
First Time Yassmittal
Yassmittal commercify
CPE cpe:2.3:a:yassmittal:commercify:1.0:*:*:*:*:*:*:*
References () https://github.com/cypherdavy/CVE-2025-29722 - () https://github.com/cypherdavy/CVE-2025-29722 - Exploit, Third Party Advisory
References () https://github.com/yassmittal/Commercify - () https://github.com/yassmittal/Commercify - Product

17 Apr 2025, 19:16

Type Values Removed Values Added
CWE CWE-352
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3

17 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-17 18:15

Updated : 2025-04-23 18:49


NVD link : CVE-2025-29722

Mitre link : CVE-2025-29722

CVE.ORG link : CVE-2025-29722


JSON object : View

Products Affected

yassmittal

  • commercify
CWE
CWE-352

Cross-Site Request Forgery (CSRF)