PT-2025-41238 · Unknown · Jhumanj Opnform

Balejin

·

Published

2025-10-08

·

Updated

2025-10-08

·

CVE-2025-11442

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions JhumanJ OpnForm versions up to 1.9.3
Description A security flaw exists in JhumanJ OpnForm. The issue involves an unknown function within the component’s API Endpoint and can lead to cross-site request forgery. The attack can be initiated remotely. While the vendor indicates API calls require authentication via Authorization Bearer Tokens, mitigating classic CSRF attacks, an attacker could exploit the flaw if they obtain the JWT through other means, such as cross-site scripting (XSS). The exploit has been publicly released.
Recommendations Versions prior to 1.9.3 should be used.

Exploit

Fix

Missing Authorization

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-11442

Affected Products

Jhumanj Opnform