PT-2025-35428 · Unknown · Koillection

Balejin

·

Published

2025-08-31

·

Updated

2025-09-01

·

CVE-2025-9747

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Koillection versions up to 1.6.18
Description A cross-site request forgery issue exists in Koillection. The issue is related to an unknown function within the assets/controllers/csrf protection controller.js file. This manipulation can be executed remotely. The exploit has been publicly disclosed. The vendor addressed this issue by switching to a newer, stateless CSRF handling mechanism.
Recommendations Upgrade to version 1.7.0 to address this issue.

Exploit

Fix

Missing Authorization

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-9747

Affected Products

Koillection