CVE-2025-28355
Last modified
CVE-2025-28355 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Personal-Management-System | Personal Management System | 1.4.65 |
References
- https://github.com/abbisQQ/CVE-2025-28355/tree/mainExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-28355?
How severe is CVE-2025-28355?
How do I fix CVE-2025-28355?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-2832A vulnerability was found in mingyuefusu 明月复苏 tushuguanlixit…5.3
- CVE-2025-2833A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. …6.9
- CVE-2025-28343striso-control-firmware 54c9722 is vulnerable to Buffer Over…7.5
- CVE-2025-28344striso-control-firmware 54c9722 is vulnerable to Buffer Over…7.5
- CVE-2025-2835A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. …5.3
- CVE-2025-28354An issue in the Printer Manager Systm of Entrust Corp Printe…6.5
- CVE-2025-28357A CRLF injection vulnerability in Neto CMS v6.313.0 through …8.8
- CVE-2025-2836The RegistrationMagic – Custom Registration Forms, User Regi…6.4
- CVE-2025-28361Unauthorized stack overflow vulnerability in Telesquare TLR-…7.5
- CVE-2025-28367mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal vi…6.5
- CVE-2025-2837Silicon Labs Gecko OS HTTP Request Handling Stack-based Buff…8.8
- CVE-2025-28371EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incor…6.5
Are you affected by CVE-2025-28355?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
