Cross-Site Request Forgery in Benner ModernaNet Affects Versions Up to 1.2.0
CVE-2025-1644
5.3MEDIUM
What is CVE-2025-1644?
A vulnerability has been identified in Benner ModernaNet versions up to 1.2.0 that allows for cross-site request forgery (CSRF) attacks through manipulation of the argument 'idItAg' in the file /DadosPessoais/SG_Gravar. This security flaw enables an attacker to exploit the system remotely, compromising the integrity of user actions and potentially leading to unauthorized changes. Users are strongly urged to upgrade to version 1.2.1 or higher to eliminate this security risk and protect their systems.
Affected Version(s)
ModernaNet 1.0
ModernaNet 1.1
ModernaNet 1.2