CVE-2025-50902

Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1.0.0 allows attackers to gain sensitive information via crafted HTTP Post message.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:old-peanut:open-shop:*:*:*:*:*:*:*:*

History

09 Oct 2025, 17:23

Type Values Removed Values Added
First Time Old-peanut
Old-peanut open-shop
CPE cpe:2.3:a:old-peanut:open-shop:*:*:*:*:*:*:*:*
References () https://gitee.com/old-peanut/wechat_applet__open_source/issues/IC95QM - () https://gitee.com/old-peanut/wechat_applet__open_source/issues/IC95QM - Exploit, Third Party Advisory

21 Aug 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
Summary
  • (es) La vulnerabilidad de Cross Site Request Forgery (CSRF) en old-peanut Open-Shop (también conocido como old-peanut/wechat_applet__open_source) hasta la versión 1.0.0 permite a los atacantes obtener información confidencial a través de mensajes HTTP Post manipulados específicamente.
CWE CWE-352

20 Aug 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-20 20:15

Updated : 2025-10-09 17:23


NVD link : CVE-2025-50902

Mitre link : CVE-2025-50902

CVE.ORG link : CVE-2025-50902


JSON object : View

Products Affected

old-peanut

  • open-shop
CWE
CWE-352

Cross-Site Request Forgery (CSRF)