First published: Fri Feb 21 2025(Updated: )
A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
UJCMS Jspxcms | >=9.0<=9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25772 has a high severity rating due to its ability to allow unauthorized account creation.
To fix CVE-2025-25772, update Jspxcms to a version that is higher than 9.5 where the vulnerability has been patched.
CVE-2025-25772 allows attackers to perform Cross-Site Request Forgery attacks that can lead to the unauthorized addition of Administrator accounts.
CVE-2025-25772 affects Jspxcms versions from 9.0 to 9.5.
Yes, CVE-2025-25772 can be exploited via crafted requests, which makes it relatively easy for attackers to use.