CVE-2025-26206

Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component
Configurations

Configuration 1 (hide)

cpe:2.3:a:selldone:storefront:1.0:*:*:*:*:*:*:*

History

07 Jul 2025, 18:28

Type Values Removed Values Added
First Time Selldone
Selldone storefront
CPE cpe:2.3:a:selldone:storefront:1.0:*:*:*:*:*:*:*
Summary
  • (es) La vulnerabilidad de Cross Site Request Forgery en sell done storefront v.1.0 permite que un atacante remoto escale privilegios a través del componente index.html
References () https://github.com/selldone/storefront/blob/main/index.html - () https://github.com/selldone/storefront/blob/main/index.html - Exploit
References () https://github.com/xibhi/CVE-2025-26206 - () https://github.com/xibhi/CVE-2025-26206 - Third Party Advisory

04 Mar 2025, 17:15

Type Values Removed Values Added
CWE CWE-352
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.0

03 Mar 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 19:15

Updated : 2025-07-07 18:28


NVD link : CVE-2025-26206

Mitre link : CVE-2025-26206

CVE.ORG link : CVE-2025-26206


JSON object : View

Products Affected

selldone

  • storefront
CWE
CWE-352

Cross-Site Request Forgery (CSRF)