A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-ajax-1 of the component Password Change Handler. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
References
Configurations
No configuration.
History
28 Apr 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://github.com/dtwin88/cve-md/blob/main/lecms%20V3.0.3/lecms_3.md - |
27 Apr 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-27 18:15
Updated : 2025-04-29 13:52
NVD link : CVE-2025-3979
Mitre link : CVE-2025-3979
CVE.ORG link : CVE-2025-3979
JSON object : View
Products Affected
No product.