CVE-2025-65778: CSRF
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-controlled Content-Type (text/html), allowing execution of attacker-supplied HTML/JS in the application's origin and enabling session/token theft and CSRF actions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65778?
CVE-2025-65778 is considered a medium severity vulnerability due to its potential for session and token theft through execution of attacker-supplied scripts.
How do I fix CVE-2025-65778?
To fix CVE-2025-65778, upgrade Wekan to version 18.16 or later.
What versions of Wekan are affected by CVE-2025-65778?
CVE-2025-65778 affects Wekan versions up to and including 18.15.
What are the potential risks of CVE-2025-65778?
The risks associated with CVE-2025-65778 include execution of malicious HTML/JS code, which can lead to unauthorized access and data theft.
Can CVE-2025-65778 be exploited remotely?
Yes, CVE-2025-65778 can be exploited remotely, as it allows attacker-controlled content to be served through uploaded attachments.