PT-2025-35428 · Unknown · Koillection

·

CVE-2025-9747

·

Published

2025-08-31

·

Updated

2025-09-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Koillection versions up to 1.6.18
Description A cross-site request forgery issue exists in Koillection. The issue is related to an unknown function within the assets/controllers/csrf protection controller.js file. This manipulation can be executed remotely. The exploit has been publicly disclosed. The vendor addressed this issue by switching to a newer, stateless CSRF handling mechanism.
Recommendations Upgrade to version 1.7.0 to address this issue.

Exploit

Fix

CSRF

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9747

Affected Products

Koillection