Authorization Bypass in withstars Books-Management-System
CVE-2025-3963
Key Information:
- Vendor
Withstars
- Status
- Vendor
- CVE Published:
- 27 April 2025
Badges
What is CVE-2025-3963?
A significant vulnerability has been identified in the withstars Books-Management-System 1.0, specifically affecting the processing within the file /admin/article/list of its Background Interface component. This flaw allows for unauthorized access due to missing authorization checks, which can be exploited remotely by attackers. As the affected product is no longer maintained, users should take immediate action to secure their systems to mitigate potential exploitation.
Affected Version(s)
Books-Management-System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved