CVE-2025-1557

A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ofcms_project:ofcms:1.1.3:*:*:*:*:*:*:*

History

04 Jun 2025, 19:14

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad clasificada como problemática en OFCMS 1.1.3. Se trata de una función desconocida. La manipulación conduce a cross-site request forgery. Es posible lanzar el ataque de forma remota. El exploit se ha hecho público y puede utilizarse.
CPE cpe:2.3:a:ofcms_project:ofcms:1.1.3:*:*:*:*:*:*:*
References () https://vuldb.com/?ctiid.296508 - () https://vuldb.com/?ctiid.296508 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.296508 - () https://vuldb.com/?id.296508 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.500269 - () https://vuldb.com/?submit.500269 - Third Party Advisory, VDB Entry
References () https://www.yuque.com/u123456789-6sobi/cdgcbq/kq7117ogyycutxo2?singleDoc#%20%E3%80%8ACSRF%20Vulnerability%20in%20OfCms%20%2F%20OfCms%E5%AD%98%E5%9C%A8CSRF%E6%BC%8F%E6%B4%9E%E3%80%8B - () https://www.yuque.com/u123456789-6sobi/cdgcbq/kq7117ogyycutxo2?singleDoc#%20%E3%80%8ACSRF%20Vulnerability%20in%20OfCms%20%2F%20OfCms%E5%AD%98%E5%9C%A8CSRF%E6%BC%8F%E6%B4%9E%E3%80%8B - Exploit
First Time Ofcms Project
Ofcms Project ofcms

22 Feb 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-22 13:15

Updated : 2025-06-04 19:14


NVD link : CVE-2025-1557

Mitre link : CVE-2025-1557

CVE.ORG link : CVE-2025-1557


JSON object : View

Products Affected

ofcms_project

  • ofcms
CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-862

Missing Authorization