PT-2026-25691 · Raytha+1 · Raytha

Daniel Basta

·

Publicado

2026-03-16

·

Atualizado

2026-03-16

·

CVE-2025-69238

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Raytha CMS versions prior to 1.4.6
Description Raytha CMS is susceptible to Cross-Site Request Forgery (CSRF) across multiple endpoints. An attacker can create a malicious website that, when visited by an authenticated user, automatically sends a POST request to an endpoint, potentially leading to unauthorized actions such as data deletion, because token verification is not enforced. The vulnerable endpoints are not specified.
Recommendations Update Raytha CMS to version 1.4.6 or later.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69238

Produtos afetados

Raytha