CVE-2025-1084

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 7, 2025
CWE ID 352
CWE ID 862

Summary

CVE-2025-1084 is a recently disclosed vulnerability affecting the Mindskip xzs-mysql 学之思开源考试系统 3.9.0. This issue is classified as problematic due to its potential for cross-site request forgery (CSRF) attacks. The exact functionality that is vulnerable has not been identified. These attacks can be launched remotely, allowing unauthorized changes to affected endpoints, potentially putting sensitive data at risk. The vendor has been notified of the disclosure but has yet to respond or provide a patch. Multiple endpoints within the system are reportedly affected.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share