Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/padayali-JD/CVE-2025-25967 |
![]() ![]() |
History
Thu, 06 Mar 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ddsn
Ddsn acora Cms |
|
CPEs | cpe:2.3:a:ddsn:acora_cms:10.1.1:*:*:*:*:*:*:* | |
Vendors & Products |
Ddsn
Ddsn acora Cms |
Tue, 04 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-352 | |
Metrics |
cvssV3_1
|
Mon, 03 Mar 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-03T00:00:00.000Z
Updated: 2025-03-04T16:49:06.467Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25967

Updated: 2025-03-04T16:48:58.094Z

Status : Analyzed
Published: 2025-03-03T19:15:35.400
Modified: 2025-03-06T12:21:35.360
Link: CVE-2025-25967

No data.