Cross-Site Request Forgery in a Leading Software Product by Popular Vendor
CVE-2025-55057

4.5MEDIUM

Key Information:

Vendor

Rumpus

Vendor
CVE Published:
17 November 2025

What is CVE-2025-55057?

A well-known Cross-Site Request Forgery (CSRF) vulnerability exists in the popular software product. This vulnerability allows attackers to trick users into performing unintended actions without their consent. By exploiting insufficient verification mechanisms, an adversary can initiate unauthorized commands on behalf of an authenticated user, potentially compromising sensitive information and user accounts. It is crucial for organizations using this product to implement CSRF mitigation techniques to secure their applications.

Affected Version(s)

FTP Server 9.0.12

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Moshe Mizrahi, Almog Cygel, Naor Yaacob
.
CVE-2025-55057 : Cross-Site Request Forgery in a Leading Software Product by Popular Vendor