CVE-2025-44186: CSRF
Published May 14, 2025
·Updated
SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.
Affected Software
2 affected components
Sourcecodester Best Employee Management System
Mayurik Best Employee Management System=1.0
Event History
May 14, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-44186?
CVE-2025-44186 is classified as a high-severity vulnerability due to its potential for Cross Site Request Forgery attacks.
2
How does CVE-2025-44186 affect the Best Employee Management System?
CVE-2025-44186 allows an attacker to perform unauthorized actions on behalf of an authenticated user through CSRF.
3
How do I fix CVE-2025-44186?
To fix CVE-2025-44186, implement CSRF tokens in forms to verify the authenticity of requests.
4
In which component of the Best Employee Management System is CVE-2025-44186 found?
CVE-2025-44186 is found in the /admin/Operation/User.php page of the Best Employee Management System.
5
Who is affected by CVE-2025-44186?
Any user of the SourceCodester Best Employee Management System 1.0 that interacts with the vulnerable component is affected by CVE-2025-44186.