PT-2025-39920 · Freshrss · Freshrss

Inverle

·

Published

2025-09-29

·

Updated

2025-09-30

·

CVE-2025-59950

CVSS v3.1

6.7

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions FreshRSS versions 1.26.3 and below
Description FreshRSS is susceptible to a double clickjacking protection bypass. An attacker can trick an administrator into promoting themselves to "admin" and logging into other users' accounts. This is achieved by exploiting a flaw in the confirmation dialog, requiring knowledge of the specific instance URL. A successful attack requires the administrator to double-click on a button within an attacker-controlled website.
Recommendations Update to version 1.27.0 or later.

Exploit

Fix

LPE

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2025-59950
GHSA-J66V-HVQX-5VH3

Affected Products

Freshrss