07FLYCMS, 07FLY-CMS, and 07FlyCRM Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in 07FLYCMS, 07FLY-CMS, and 07FlyCRM versions through 1.3.9. This vulnerability allows for the manipulation of requests in a way that could be exploited remotely, without the need for authentication. The issue arises because the application does not adequately verify whether a request was intentionally made by the user.

Impact

Exploitation of this vulnerability allows for cross-site request forgery, where an attacker can trick a user into performing actions they did not intend to.

Reproduction

To reproduce this vulnerability, send a request to the 'del.html' endpoint of the OaLeave component with a valid 'id' parameter. This request must be made without proper verification, taking advantage of the application's lack of CSRF protection.

Added: Jul 6, 2025, 9:17 AM
Updated: Jul 6, 2025, 9:17 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
7.9
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.