CVE-2025-36728: SimpleHelp Cross Site Request Forgery
Published Jul 25, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11.
Affected Software
1 affected component
Simple-help Simplehelp<5.5.11
Event History
Jul 25, 2025
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 30, 57622
Event
via NVD·12:53 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-36728?
CVE-2025-36728 has a medium severity level due to its potential for unauthorized actions on behalf of authenticated users.
2
How do I fix CVE-2025-36728?
To fix CVE-2025-36728, upgrade Simplehelp to version 5.5.11 or later.
3
What type of vulnerability is CVE-2025-36728?
CVE-2025-36728 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
Which versions of Simplehelp are affected by CVE-2025-36728?
CVE-2025-36728 affects versions of Simplehelp prior to 5.5.11.
5
What are the potential impacts of exploiting CVE-2025-36728?
Exploiting CVE-2025-36728 can allow attackers to perform sensitive actions without user consent.