Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5918 | Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/R2og/Sun-jialiang/tree/main/9/readme.md |
|
History
Tue, 15 Apr 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
07fly
07fly 07flycms |
|
| CPEs | cpe:2.3:a:07fly:07flycms:1.3.9:*:*:*:*:*:*:* | |
| Vendors & Products |
07fly
07fly 07flycms |
Tue, 04 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Fri, 28 Feb 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-04T15:44:16.900Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25379
Updated: 2025-03-04T15:44:03.335Z
Status : Analyzed
Published: 2025-02-28T23:15:10.790
Modified: 2025-04-15T20:10:40.157
Link: CVE-2025-25379
No data.
OpenCVE Enrichment
No data.
EUVD