CVE-2025-53897: Kiteworks MFT has a Cross-Site Request Forgery (CSRF) vulnerability
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain access to log information from the system by tricking an administrator into browsing a specifically crafted fake page of Kiteworks MFT. This issue has been patched in version 9.1.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53897?
The severity of CVE-2025-53897 is critical due to the potential for unauthorized access to sensitive log information.
How do I fix CVE-2025-53897?
To fix CVE-2025-53897, upgrade your Kiteworks MFT software to version 9.1.0 or later.
Who is affected by CVE-2025-53897?
Organizations using Kiteworks MFT versions prior to 9.1.0 are affected by CVE-2025-53897.
What type of attack is associated with CVE-2025-53897?
CVE-2025-53897 is associated with an external attack that can exploit social engineering to access log information.
What should administrators do to mitigate CVE-2025-53897?
Administrators should educate users on recognizing phishing attempts and ensure the software is updated to the latest version to mitigate CVE-2025-53897.