Cross-Site Request Forgery Vulnerability in Simplehelp by Simplehelp
CVE-2025-36728

6.3MEDIUM

Key Information:

Vendor

Simplehelp

Vendor
CVE Published:
25 July 2025

What is CVE-2025-36728?

A CSRF vulnerability exists in Simplehelp which could allow an attacker to perform unauthorized actions on behalf of authenticated users. This issue affects versions up to 5.5.10 of Simplehelp, representing a significant risk of exploitation if appropriate security measures are not in place. Users should ensure they are running the latest version to mitigate potential security threats.

Affected Version(s)

Simplehelp 0 < 5.5.11

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36728 : Cross-Site Request Forgery Vulnerability in Simplehelp by Simplehelp