PT-2025-18007 · Unknown · Dazhouda Lecms
Dtwin
·
Published
2025-04-27
·
Updated
2025-05-12
·
CVE-2025-3979
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
dazhouda lecms version 3.0.3
Description
A problematic issue has been found in the Password Change Handler component, affecting the /index.php?my-password-ajax-1 file. This leads to cross-site request forgery and can be initiated remotely. The exploit has been publicly disclosed.
Recommendations
For dazhouda lecms version 3.0.3, consider disabling the
my-password-ajax-1 functionality in the Password Change Handler component until a patch is available. Restrict access to the /index.php?my-password-ajax-1 endpoint to minimize the risk of exploitation.Exploit
Fix
Missing Authorization
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dazhouda Lecms