A Cross-Site Request Forgery (CSRF) in the /admin/admin.inc.php component of EasyImages 2.0 v2.8.6 and below allows attackers to escalate privileges to Administrator via user interaction with a malicious web page.
References
| Link | Resource |
|---|---|
| https://congsec.cn/?id=20251104215007-yjddwx1 | Exploit Third Party Advisory |
| https://gist.github.com/CongSec/a6c8b15878f19647dbd26c22b47bac65 | Exploit Third Party Advisory |
Configurations
History
15 Dec 2025, 19:29
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://congsec.cn/?id=20251104215007-yjddwx1 - Exploit, Third Party Advisory | |
| References | () https://gist.github.com/CongSec/a6c8b15878f19647dbd26c22b47bac65 - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:easyimages2.0_project:easyimages2.0:*:*:*:*:*:*:*:* | |
| First Time |
Easyimages2.0 Project
Easyimages2.0 Project easyimages2.0 |
15 Dec 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| CWE | CWE-352 |
11 Dec 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-11 17:15
Updated : 2025-12-15 19:29
NVD link : CVE-2025-65472
Mitre link : CVE-2025-65472
CVE.ORG link : CVE-2025-65472
JSON object : View
Products Affected
easyimages2.0_project
- easyimages2.0
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
