Cross-Site Request Forgery in Talassoft Industrial Management Software by TMT Machine Industry and Trade Ltd. Co.
CVE-2026-18780

7.1HIGH

What is CVE-2026-18780?

A cross-site request forgery (CSRF) vulnerability exists in Talassoft Industrial Management Software developed by TMT Machine Industry and Trade Ltd. Co. This security flaw allows unauthorized commands to be transmitted from a user that the web application trusts, potentially leading to unauthorized access and actions within the software. The vulnerability affects versions 4 up to 15, making users susceptible to various security threats if the software is not updated.

Affected Version(s)

Talassoft Industrial Management Software V.4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Efe Ă–zel
Cemil Sefa Ă–zcan
FORDEFENCE
.