Daicuo · Daicuo · CVE-2025-6865
Name of the Vulnerable Software and Affected Versions:
DaiCuo versions 1.3.13 and earlier
Description:
A problematic issue was found in DaiCuo, affecting an unknown part of the file "/admin.php/addon/index". This issue leads to cross-site request forgery. The attack can be initiated remotely.
Recommendations:
For DaiCuo versions 1.3.13 and earlier, as a temporary workaround, consider restricting access to the "/admin.php/addon/index" endpoint until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.