CVE-2025-25967

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.
References
Link Resource
https://github.com/padayali-JD/CVE-2025-25967 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ddsn:acora_cms:10.1.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-03 19:15

Updated : 2025-03-06 12:25


NVD link : CVE-2025-25967

Mitre link : CVE-2025-25967

CVE.ORG link : CVE-2025-25967


JSON object : View

Products Affected

ddsn

  • acora_cms
CWE
CWE-352

Cross-Site Request Forgery (CSRF)