CVE-2025-29722

A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:yassmittal:commercify:1.0:*:*:*:*:*:*:*

History

23 Apr 2025, 18:49

Type Values Removed Values Added
CPE cpe:2.3:a:yassmittal:commercify:1.0:*:*:*:*:*:*:*
First Time Yassmittal commercify
Yassmittal
References () https://github.com/cypherdavy/CVE-2025-29722 - () https://github.com/cypherdavy/CVE-2025-29722 - Exploit, Third Party Advisory
References () https://github.com/yassmittal/Commercify - () https://github.com/yassmittal/Commercify - Product

17 Apr 2025, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-17 18:15

Updated : 2025-04-23 18:49


NVD link : CVE-2025-29722

Mitre link : CVE-2025-29722


JSON object : View

Products Affected

yassmittal

  • commercify
CWE

No CWE.