CVE-2025-61547

Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 18.34. The application does not implement proper CSRF tokens or other other protective measures, allowing a remote attacker to trick authenticated users into unknowingly executing unintended actions within their session. This can lead to unauthorized data modification such as credential updates.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:edubusinesssolutions:print_shop_pro_webdesk:18.34:*:*:*:*:*:*:*

History

22 Jan 2026, 15:28

Type Values Removed Values Added
CPE cpe:2.3:a:edubusinesssolutions:print_shop_pro_webdesk:18.34:*:*:*:*:*:*:*
First Time Edubusinesssolutions print Shop Pro Webdesk
Edubusinesssolutions
References () https://github.com/chndlrx/vulnerability-disclosures/tree/main/CVE-2025-61547 - () https://github.com/chndlrx/vulnerability-disclosures/tree/main/CVE-2025-61547 - Exploit, Third Party Advisory

08 Jan 2026, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
CWE CWE-352

08 Jan 2026, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-08 17:15

Updated : 2026-01-22 15:28


NVD link : CVE-2025-61547

Mitre link : CVE-2025-61547

CVE.ORG link : CVE-2025-61547


JSON object : View

Products Affected

edubusinesssolutions

  • print_shop_pro_webdesk
CWE
CWE-352

Cross-Site Request Forgery (CSRF)