CVE-2025-25967

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.
References
Link Resource
https://github.com/padayali-JD/CVE-2025-25967 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ddsn:acora_cms:10.1.1:*:*:*:*:*:*:*

History

06 Mar 2025, 12:21

Type Values Removed Values Added
First Time Ddsn acora Cms
Ddsn
CPE cpe:2.3:a:ddsn:acora_cms:10.1.1:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References () https://github.com/padayali-JD/CVE-2025-25967 - () https://github.com/padayali-JD/CVE-2025-25967 - Third Party Advisory

03 Mar 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 19:15

Updated : 2025-03-06 12:21


NVD link : CVE-2025-25967

Mitre link : CVE-2025-25967


JSON object : View

Products Affected

ddsn

  • acora_cms
CWE

No CWE.