PT-2025-38415 · Smartvista · Smartvista Suite

C2At3

·

Published

2025-09-18

·

Updated

2025-09-19

·

CVE-2025-50255

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Smartvista BackOffice SmartVista Suite version 2.2.22
Description The software contains a Cross Site Request Forgery (CSRF) flaw. A crafted GET request can trigger the flaw.
Recommendations Apply any available updates to address the issue in Smartvista BackOffice SmartVista Suite version 2.2.22.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-50255

Affected Products

Smartvista Suite