Cross-Site Request Forgery in JhumanJ OpnForm API Endpoint
CVE-2025-11442
Key Information:
Badges
What is CVE-2025-11442?
A security issue has been identified in JhumanJ OpnForm versions up to 1.9.3, particularly concerning an unknown function within the component's API Endpoint. This vulnerability exposes the application to cross-site request forgery (CSRF) attacks, which can be executed remotely. Although the vendor asserts that API calls necessitate authentication via Authorization Bearer Tokens, classic CSRF threats may not apply. However, an attacker may exploit the vulnerability by acquiring the JWT (JSON Web Token) through methods such as cross-site scripting (XSS). Consequently, strong security measures are essential to prevent unauthorized access and maintain data integrity.
Affected Version(s)
OpnForm 1.9.0
OpnForm 1.9.1
OpnForm 1.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved