← Retour aux CVEs
CVE-2025-60535
HIGH7.3
Description
A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to execute arbitrary operations via a crafted GET request.
Details CVE
Score CVSS v3.17.3
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie10/14/2025
Derniere modification10/14/2025
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-352
References
http://wallos.com(cve@mitre.org)
https://github.com/ellite/Wallos/(cve@mitre.org)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.