Vulnerability Description
A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xuxueli | Xxl-Api | <= 1.3.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/LockeTom/77fb982a49dee956101810bbefa09fb4ExploitThird Party Advisory
- https://github.com/xuxueli/xxl-api/issues/64ExploitIssue TrackingVendor Advisory
FAQ
What is CVE-2025-60645?
CVE-2025-60645 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.
How severe is CVE-2025-60645?
CVE-2025-60645 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-60645?
Check the references section above for vendor advisories and patch information. Affected products include: Xuxueli Xxl-Api.