CVE-2025-28355
Last modified
CVE-2025-28355 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Personal-Management-System | Personal Management System | 1.4.65 |
References
- https://github.com/abbisQQ/CVE-2025-28355/tree/mainExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-28355?
How severe is CVE-2025-28355?
How do I fix CVE-2025-28355?
Are you affected by CVE-2025-28355?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
