Cross-Site Request Forgery in Iroha Board by IrohaSoft
CVE-2025-48497

5.1MEDIUM

Key Information:

Vendor
CVE Published:
26 June 2025

What is CVE-2025-48497?

Iroha Board versions v0.10.12 and earlier are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This flaw allows attackers to exploit the system if a logged-in user inadvertently accesses a specially crafted URL. Consequently, malicious actors may manipulate the application to register arbitrary learning histories, posing a significant risk to user data integrity and application security. It's crucial for users to be aware of this vulnerability and take protective measures to avoid exposure.

Affected Version(s)

iroha Board versions v0.10.12 and earlier

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

CVSS V3.0

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48497 : Cross-Site Request Forgery in Iroha Board by IrohaSoft