CVE-2025-3687
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 16, 2025
CWE ID 352
CWE ID 862
Summary
CVE-2025-3687: A problematic vulnerability has been identified in the Sticky Notes Handler component of misstt123 oasys 1.0. This issue allows for cross-site request forgery, potentially enabling remote attacks on some unknown functionality. The exploit for this vulnerability has been made public, increasing the risk for exploitation. Unfortunately, due to the product's rolling release model, no specific version details for affected or updated releases have been disclosed. Users are strongly encouraged to apply the latest security patches as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Omgeo OASYS
Affected Vendors
- Depository Trust & Clearing