Cross Site Request Forgery (CSRF) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to cause a denial of service via function handle_interface_POST_and_status.
References
| Link | Resource |
|---|---|
| https://gh0stmezh.wordpress.com/2025/12/05/cve-2025-65573/ | Exploit Third Party Advisory |
| https://github.com/AllskyTeam/allsky | Product |
| https://github.com/AllskyTeam/allsky/blob/master/html/includes/dashboard_LAN.php | Product |
| https://github.com/AllskyTeam/allsky/blob/master/html/includes/dashboard_WLAN.php | Product |
| https://github.com/AllskyTeam/allsky/blob/master/html/includes/functions.php | Product |
| https://gh0stmezh.wordpress.com/2025/12/05/cve-2025-65573/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-12-09 19:15
Updated : 2025-12-16 20:00
NVD link : CVE-2025-65573
Mitre link : CVE-2025-65573
CVE.ORG link : CVE-2025-65573
JSON object : View
Products Affected
allskyteam
- allsky
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
