PT-2025-34886 · Ebay · Bevy Event Service

Deep1Chil

·

Published

2025-08-27

·

Updated

2025-08-27

·

CVE-2025-54598

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: The Bevy Event service versions through 2025-07-22
Description: The Bevy Event service, used for eBay Seller Events and other activities, is susceptible to a Cross-Site Request Forgery (CSRF) issue. This flaw allows an attacker to delete all notifications by exploiting the /notifications/delete/ API endpoint.
Recommendations: Versions through 2025-07-22: Mitigate the issue by implementing CSRF protection mechanisms, such as synchronizer tokens, to validate requests originating from trusted sources.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-54598

Affected Products

Bevy Event Service