tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request.
References
| Link | Resource |
|---|---|
| https://github.com/xujeff/tianti/issues/39 | Exploit Third Party Advisory Issue Tracking |
| https://github.com/xujeff/tianti/issues/39 | Exploit Third Party Advisory Issue Tracking |
Configurations
History
No history.
Information
Published : 2025-03-10 22:15
Updated : 2025-05-21 19:34
NVD link : CVE-2025-27910
Mitre link : CVE-2025-27910
CVE.ORG link : CVE-2025-27910
JSON object : View
Products Affected
tianti_project
- tianti
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
