A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-ajax-1 of the component Password Change Handler. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/dtwin88/cve-md/blob/main/lecms%20V3.0.3/lecms_3.md | Exploit |
https://vuldb.com/?ctiid.306315 | Permissions Required VDB Entry |
https://vuldb.com/?id.306315 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.557787 | Third Party Advisory VDB Entry |
https://github.com/dtwin88/cve-md/blob/main/lecms%20V3.0.3/lecms_3.md | Exploit |
Configurations
History
12 May 2025, 19:06
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:lecms:lecms:3.0.3:*:*:*:*:*:*:* | |
References | () https://github.com/dtwin88/cve-md/blob/main/lecms%20V3.0.3/lecms_3.md - Exploit | |
References | () https://vuldb.com/?ctiid.306315 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.306315 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.557787 - Third Party Advisory, VDB Entry | |
First Time |
Lecms lecms
Lecms |
28 Apr 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/dtwin88/cve-md/blob/main/lecms%20V3.0.3/lecms_3.md - | |
Summary |
|
27 Apr 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-27 18:15
Updated : 2025-05-12 19:06
NVD link : CVE-2025-3979
Mitre link : CVE-2025-3979
CVE.ORG link : CVE-2025-3979
JSON object : View
Products Affected
lecms
- lecms