CVE-2025-6865 Information

Description

A vulnerability which was classified as problematic was found in DaiCuo up to 1.3.13. This affects an unknown part of the file /admin.php/addon/index. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Reference

https://github.com/wwm1995/weiming_wang/blob/main/daicuocms_1.md https://vuldb.com/?ctiid.314337 https://vuldb.com/?id.314337 https://vuldb.com/?submit.603563

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

4.3

CNNVD-202506-3691 (Published: 2025-06-29)

Share on: