Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin.
References
| Link | Resource |
|---|---|
| https://blog.teedy.io/ | Broken Link |
| https://github.com/samplev45/CVE-2025-22963 | Third Party Advisory |
| https://github.com/sismics/docs/releases/tag/v1.11 | Release Notes |
| https://github.com/sota70/teedy-v1.11-csrf | Broken Link |
Configurations
History
No history.
Information
Published : 2025-01-13 16:15
Updated : 2025-10-07 16:53
NVD link : CVE-2025-22963
Mitre link : CVE-2025-22963
CVE.ORG link : CVE-2025-22963
JSON object : View
Products Affected
sismics
- teedy
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
