CVE-2025-60645: CSRF
Published Nov 12, 2025
·Updated
A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.
Affected Software
2 affected components
xxl-api xxl-api
Xuxueli Xxl-api<=1.3.0
Event History
Nov 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-60645?
CVE-2025-60645 is classified as a high severity vulnerability due to its potential to allow unauthorized user additions.
2
How do I fix CVE-2025-60645?
To fix CVE-2025-60645, upgrade xxl-api to a version later than 1.3.0 where the CSRF vulnerability is patched.
3
What type of vulnerability is CVE-2025-60645?
CVE-2025-60645 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
What versions of xxl-api are affected by CVE-2025-60645?
xxl-api versions up to and including 1.3.0 are affected by CVE-2025-60645.
5
What are the potential impacts of CVE-2025-60645?
The potential impacts of CVE-2025-60645 include unauthorized modification of the management module and adding malicious users.