Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.
History

Thu, 06 Mar 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Ddsn
Ddsn acora Cms
CPEs cpe:2.3:a:ddsn:acora_cms:10.1.1:*:*:*:*:*:*:*
Vendors & Products Ddsn
Ddsn acora Cms

Tue, 04 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 18:45:00 +0000

Type Values Removed Values Added
Description Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-03-03T00:00:00.000Z

Updated: 2025-03-04T16:49:06.467Z

Reserved: 2025-02-07T00:00:00.000Z

Link: CVE-2025-25967

cve-icon Vulnrichment

Updated: 2025-03-04T16:48:58.094Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-03T19:15:35.400

Modified: 2025-03-06T12:21:35.360

Link: CVE-2025-25967

cve-icon Redhat

No data.