CVE Database · CVE-2025-29722
CVSS v3.1
6.3
EPSS
0.18%
Published
Apr 17, 2025
Modified
Apr 23, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:LWeaknesses (CWE)
Affected Products (1)
References (2)