Cross-Site Request Forgery Vulnerability in XXL-API by xuxueli
CVE-2025-60645
6.5MEDIUM
What is CVE-2025-60645?
A vulnerability in the XXL-API, version 1.3.0, exposes the system to Cross-Site Request Forgery attacks. This allows attackers to execute unauthorized actions, such as adding arbitrary users to the management module through specially crafted GET requests. Such exploitation could severely impact the integrity and security of user data and application configurations.
