Vulnerability Description
Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 07Fly | 07Flycms | 1.3.9 |
Related Weaknesses (CWE)
References
- https://github.com/R2og/Sun-jialiang/tree/main/9/readme.mdBroken Link
- https://github.com/R2og/Sun-jialiang/tree/main/9/readme.mdBroken Link
FAQ
What is CVE-2025-25379?
CVE-2025-25379 is a vulnerability with a CVSS score of 9.6 (CRITICAL). Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component.
How severe is CVE-2025-25379?
CVE-2025-25379 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-25379?
Check the references section above for vendor advisories and patch information. Affected products include: 07Fly 07Flycms.