PT-2025-32489 · Unknown · Atjiu Pybbs
Zast.Ai
·
Published
2025-08-10
·
Updated
2025-08-10
·
CVE-2025-8814
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
atjiu pybbs versions up to 6.0.0
Description:
A problematic issue exists in the
setCookie function within the src/main/java/co/yiiu/pybbs/util/CookieUtil.java file. This allows for cross-site request forgery, potentially initiated remotely. The exploit has been publicly disclosed.Recommendations:
Apply the patch 8aa2bb1aef3346e49aec6358edf5e47ce905ae7b to resolve this issue.
Exploit
Fix
Missing Authorization
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Atjiu Pybbs