Cross-Site Request Forgery Vulnerability in JPACookieShop by jerryshensjf
CVE-2025-8223
Key Information:
- Vendor
Jerryshensjf
- Vendor
- CVE Published:
- 27 July 2025
Badges
What is CVE-2025-8223?
A cross-site request forgery vulnerability exists in the JPACookieShop application, specifically in the AdminTypeCustController.java file. This vulnerability allows an attacker to manipulate requests initiated by unsuspecting users, potentially executing unauthorized actions on behalf of the victim. The attack can be executed remotely, increasing the risk of exploitation. As this product does not utilize versioning, identifying specific affected or unaffected versions remains a challenge, making it imperative for users to assess their deployments for potential exposure.
Affected Version(s)
JPACookieShop ่็ณๅๅJPA็ 24a15c02b4f75042c9f7f615a3fed2ec1cefb999
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved