V
olmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none
References
| Link | Resource |
|---|---|
| https://github.com/Volmarg/personal-management-system | Product |
| https://github.com/Volmarg/personal-management-system/issues/149 | Issue Tracking |
| https://github.com/abbisQQ/CVE-2025-28355/tree/main | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
20 Jun 2025, 16:19
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Personal-management-system
Personal-management-system personal Management System |
|
| Summary |
|
|
| References | () https://github.com/Volmarg/personal-management-system - Product | |
| References | () https://github.com/Volmarg/personal-management-system/issues/149 - Issue Tracking | |
| References | () https://github.com/abbisQQ/CVE-2025-28355/tree/main - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:personal-management-system:personal_management_system:1.4.65:*:*:*:*:*:*:* |
18 Apr 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-04-18 19:15
Updated : 2025-06-20 16:19
NVD link : CVE-2025-28355
Mitre link : CVE-2025-28355
CVE.ORG link : CVE-2025-28355
JSON object : View
Products Affected
CWE
CWE-352
Cross-Site Request Forgery (CSRF)