CVE-2025-25772: CSRF
Published Feb 21, 2025
·Updated
A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.
Affected Software
2 affected components
Jspxcms Jspxcms>=9.0<=9.5
Ujcms Jspxcms>=9.0.0<=9.5.0
Event History
Feb 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25772?
CVE-2025-25772 has a high severity rating due to its ability to allow unauthorized account creation.
2
How do I fix CVE-2025-25772?
To fix CVE-2025-25772, update Jspxcms to a version that is higher than 9.5 where the vulnerability has been patched.
3
What impact does CVE-2025-25772 have on Jspxcms?
CVE-2025-25772 allows attackers to perform Cross-Site Request Forgery attacks that can lead to the unauthorized addition of Administrator accounts.
4
Which versions of Jspxcms are affected by CVE-2025-25772?
CVE-2025-25772 affects Jspxcms versions from 9.0 to 9.5.
5
Is CVE-2025-25772 easy to exploit?
Yes, CVE-2025-25772 can be exploited via crafted requests, which makes it relatively easy for attackers to use.