CVE-2025-60645 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.
Medium CVSS: 6.5

CVE-2025-60645

A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.
Vendor
Xuxueli
Product
Xxl-api
CWE
CWE-352
Yayın Tarihi
2025-11-12 18:15:35
Güncelleme
2025-12-03 21:33:51
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar