CVE-2025-7078: 07FLYCMS/07FLY-CMS/07FlyCRM cross-site request forgery
A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This product is published under multiple names. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7078?
CVE-2025-7078 is classified as problematic due to its potential for cross-site request forgery.
How do I fix CVE-2025-7078?
To fix CVE-2025-7078, update the affected software to version 1.4.0 or later.
What software is affected by CVE-2025-7078?
CVE-2025-7078 affects 07FLYCMS, 07FLY-CMS, and 07FlyCRM versions up to 1.3.9.
Can CVE-2025-7078 be exploited remotely?
Yes, CVE-2025-7078 can be exploited remotely through cross-site request forgery.
What is cross-site request forgery related to CVE-2025-7078?
Cross-site request forgery in the context of CVE-2025-7078 allows an attacker to perform unauthorized actions on behalf of a user.