PT-2026-25691 · Raytha+1 · Raytha
Daniel Basta
·
Publicado
2026-03-16
·
Atualizado
2026-03-16
·
CVE-2025-69238
CVSS v4.0
6.9
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Raytha CMS versions prior to 1.4.6
Description
Raytha CMS is susceptible to Cross-Site Request Forgery (CSRF) across multiple endpoints. An attacker can create a malicious website that, when visited by an authenticated user, automatically sends a POST request to an endpoint, potentially leading to unauthorized actions such as data deletion, because token verification is not enforced. The vulnerable endpoints are not specified.
Recommendations
Update Raytha CMS to version 1.4.6 or later.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Raytha