CVE-2025-3687

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 16, 2025
CWE ID 352
CWE ID 862

Summary

CVE-2025-3687: A problematic vulnerability has been identified in the Sticky Notes Handler component of misstt123 oasys 1.0. This issue allows for cross-site request forgery, potentially enabling remote attacks on some unknown functionality. The exploit for this vulnerability has been made public, increasing the risk for exploitation. Unfortunately, due to the product's rolling release model, no specific version details for affected or updated releases have been disclosed. Users are strongly encouraged to apply the latest security patches as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Omgeo OASYS

Affected Vendors

  • Depository Trust & Clearing