PT-2025-36937 · Listmonk · Listmonk

R3Verii

·

Published

2025-09-09

·

Updated

2025-11-09

·

CVE-2025-58430

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions listmonk versions 1.1.0 and earlier
Description listmonk, a standalone newsletter and mailing list manager, is susceptible to a chain of vulnerabilities involving Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS). Specifically, the nonce value included in HTTP requests, alongside the session cookie session, is not validated by the backend. Removing this nonce allows requests to be processed, which, when combined with other vulnerabilities, can lead to critical issues such as improper admin account creation. The lack of a SameSite cookie policy further exacerbates the risk, potentially enabling exploitation through malicious websites. Exploitation involves chaining CSRF and XSS to execute arbitrary code in the victim's browser, ultimately allowing an attacker to create new administrative accounts.
Recommendations Versions prior to 1.1.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-58430
GHSA-RF24-WG77-GQ7W
GO-2025-3943
OPENSUSE-SU-2025:15564-1
SUSE-SU-2025:03289-1

Affected Products

Listmonk