PT-2025-46997 · Codecanyon · Saleserp

4M3Rr0R

·

Published

2025-11-14

·

Updated

2025-11-24

·

CVE-2025-13177

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bdtask/CodeCanyon SalesERP versions up to 20250728
Description A cross-site request forgery issue exists in Bdtask/CodeCanyon SalesERP. The issue affects an unspecified component and allows for remote execution of attacks. The exploit is publicly available. The vendor was notified of this issue but did not provide a response.
Recommendations Versions up to 20250728 should be updated when a fix becomes available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-13177

Affected Products

Saleserp