CVE-2025-28355

V

olmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none

Configurations

Configuration 1 (hide)

cpe:2.3:a:personal-management-system:personal_management_system:1.4.65:*:*:*:*:*:*:*

History

20 Jun 2025, 16:19

Type Values Removed Values Added
First Time Personal-management-system
Personal-management-system personal Management System
Summary
  • (es) Volmarg Personal Management System 1.4.65 es vulnerable a Cross-Site Request Forgery (CSRF), lo que permite a los atacantes ejecutar código arbitrario y obtener información confidencial a través del atributo de cookie SameSite cuyo valor predeterminado es ninguno.
References () https://github.com/Volmarg/personal-management-system - () https://github.com/Volmarg/personal-management-system - Product
References () https://github.com/Volmarg/personal-management-system/issues/149 - () https://github.com/Volmarg/personal-management-system/issues/149 - Issue Tracking
References () https://github.com/abbisQQ/CVE-2025-28355/tree/main - () https://github.com/abbisQQ/CVE-2025-28355/tree/main - Exploit, Third Party Advisory
CPE cpe:2.3:a:personal-management-system:personal_management_system:1.4.65:*:*:*:*:*:*:*

18 Apr 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-18 19:15

Updated : 2025-06-20 16:19


NVD link : CVE-2025-28355

Mitre link : CVE-2025-28355

CVE.ORG link : CVE-2025-28355


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)