Cross-Site Request Forgery in Iroha Board by IrohaSoft
CVE-2025-48497
5.1MEDIUM
What is CVE-2025-48497?
Iroha Board versions v0.10.12 and earlier are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This flaw allows attackers to exploit the system if a logged-in user inadvertently accesses a specially crafted URL. Consequently, malicious actors may manipulate the application to register arbitrary learning histories, posing a significant risk to user data integrity and application security. It's crucial for users to be aware of this vulnerability and take protective measures to avoid exposure.
Affected Version(s)
iroha Board versions v0.10.12 and earlier
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
CVSS V3.0
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved