{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-3964","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2025-04-26T07:03:42.042Z","datePublished":"2025-04-27T09:00:05.987Z","dateUpdated":"2025-04-28T15:32:54.128Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2025-04-27T09:00:05.987Z"},"title":"withstars Books-Management-System Article del cross-site request forgery","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-352","lang":"en","description":"Cross-Site Request Forgery"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-862","lang":"en","description":"Missing Authorization"}]}],"affected":[{"vendor":"withstars","product":"Books-Management-System","versions":[{"version":"1.0","status":"affected"}],"modules":["Article Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability, which was classified as problematic, was found in withstars Books-Management-System 1.0. Affected is an unknown function of the file /api/article/del of the component Article Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer."},{"lang":"de","value":"Es wurde eine Schwachstelle in withstars Books-Management-System 1.0 gefunden. Sie wurde als problematisch eingestuft. Es betrifft eine unbekannte Funktion der Datei /api/article/del der Komponente Article Handler. Mittels dem Manipulieren mit unbekannten Daten kann eine cross-site request forgery-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":4.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":4.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":5,"vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N"}}],"timeline":[{"time":"2025-04-26T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2025-04-26T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2025-04-26T09:08:56.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Caigosec (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.306300","name":"VDB-306300 | withstars Books-Management-System Article del cross-site request forgery","tags":["vdb-entry"]},{"url":"https://vuldb.com/?ctiid.306300","name":"VDB-306300 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.557239","name":"Submit #557239 | https://github.com/withstars/Blog-System Blog-System 1.0 Cross-Site Request Forgery","tags":["third-party-advisory"]},{"url":"https://github.com/caigo8/CVE-md/blob/main/Blog-System/CSRF.md","tags":["exploit"]}],"tags":["unsupported-when-assigned"]},"adp":[{"references":[{"url":"https://github.com/caigo8/CVE-md/blob/main/Blog-System/CSRF.md","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-04-28T15:32:48.961341Z","id":"CVE-2025-3964","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-04-28T15:32:54.128Z"}}]}}