Access Control Vulnerability in JhumanJ OpnForm Software
CVE-2025-11440
Key Information:
Badges
What is CVE-2025-11440?
A serious access control vulnerability exists in JhumanJ's OpnForm up to version 1.9.3. This flaw is present in an unknown function within the file '/edit', where improper access controls can be exploited. The vulnerability can be exploited remotely, making it a significant risk to exposed systems. The issue has been publicly disclosed, emphasizing the need for users to apply the provided patch (b15e29021d326be127193a5dbbd528c4e37e6324) to mitigate potential attacks and secure their applications.
Affected Version(s)
OpnForm 1.9.0
OpnForm 1.9.1
OpnForm 1.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved