Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20135 | A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This product is published under multiple names. The vendor was contacted early about this disclosure but did not respond in any way. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 01 Aug 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
07fly customer Relationship Management
|
|
| CPEs | cpe:2.3:a:07fly:07flycms:*:*:*:*:*:*:*:* cpe:2.3:a:07fly:customer_relationship_management:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
07fly customer Relationship Management
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 07 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 06 Jul 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This product is published under multiple names. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | 07FLYCMS/07FLY-CMS/07FlyCRM cross-site request forgery | |
| Weaknesses | CWE-352 CWE-862 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-07-07T16:21:20.599Z
Reserved: 2025-07-05T12:34:26.238Z
Link: CVE-2025-7078
Updated: 2025-07-07T16:21:10.696Z
Status : Undergoing Analysis
Published: 2025-07-06T09:15:23.400
Modified: 2025-08-01T22:28:49.550
Link: CVE-2025-7078
No data.
OpenCVE Enrichment
Updated: 2025-07-13T21:08:18Z
EUVD