Cross-Site Request Forgery Vulnerability in OFCMS by Unknown Vendor
CVE-2025-1557
Key Information:
- Vendor
- Unknown Vendor
- Status
- Ofcms
- Vendor
- CVE Published:
- 22 February 2025
Badges
Summary
A cross-site request forgery (CSRF) vulnerability has been identified in OFCMS version 1.1.3, which allows an attacker to execute unauthorized actions on behalf of an authenticated user. This issue arises from insufficient validation of requests, enabling attackers to initiate remote exploits. As this vulnerability has been publicly disclosed, it poses a significant risk to users and administrators of the platform, compelling immediate attention and mitigation strategies.
Affected Version(s)
OFCMS 1.1.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved