ZeroHour

CVE-2025-29722

PoC
CVSS 3.1
6.3 medium
EPSS
<1%p9
Published
()
Modified
Description

A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.

Vendors
yassmittal
Products
commercify
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.