CVE-2025-25770: CSRF
Published Feb 21, 2025
·Updated
Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyUserController.java.
Affected Software
2 affected components
Wangmarket Wangmarket>=4.10<=5.0
Wang.market Wangmarket>=4.10<=5.0
Event History
Feb 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25770?
CVE-2025-25770 is classified as a medium severity vulnerability due to its ability to execute unauthorized actions via Cross-Site Request Forgery.
2
How do I fix CVE-2025-25770?
To fix CVE-2025-25770, you should implement anti-CSRF tokens in forms and verify requests to ensure they originate from authenticated users.
3
What versions of Wangmarket are affected by CVE-2025-25770?
CVE-2025-25770 affects Wangmarket versions from 4.10 to 5.0.
4
What type of vulnerability is CVE-2025-25770?
CVE-2025-25770 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Where is the vulnerability located in Wangmarket for CVE-2025-25770?
The vulnerability in CVE-2025-25770 is located in the component /agency/AgencyUserController.java of Wangmarket.