CVE-2025-64515
Last modified
CVE-2025-64515 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data fields are dynamically set to readonly/disabled can be modified by malicious users deliberately trying to modify data they're not supposed to. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data fields are dynamically set to readonly/disabled can be modified by malicious users deliberately trying to modify data they're not supposed to. For regular users, the form fields are marked as readonly and cannot be modified through the user interface. This issue has been patched in versions 3.2.7 and 3.3.3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Maykinmedia | Open Forms | < 3.2.7 |
| Maykinmedia | Open Forms | >= 3.3.0, < 3.3.3 |
References
- https://github.com/open-formulieren/open-forms/security/advisories/GHSA-cp63-63mq-5wvfPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-64515?
How severe is CVE-2025-64515?
How do I fix CVE-2025-64515?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-64508Bugsink is a self-hosted error tracking tool. In versions pr…7.5
- CVE-2025-64509Bugsink is a self-hosted error tracking tool. In versions pr…7.5
- CVE-2025-6451A vulnerability was found in code-projects Simple Online Hot…9.8
- CVE-2025-64511MaxKB is an open-source AI assistant for enterprise. In vers…8.8
- CVE-2025-64512Pdfminer.six is a community maintained fork of the original …7.8
- CVE-2025-64513Milvus is an open-source vector database built for generativ…9.3
- CVE-2025-64516GLPI is a free asset and IT management software package. Pri…7.5
- CVE-2025-64517sudo-rs is a memory safe implementation of sudo and su writt…4.4
- CVE-2025-64518The CycloneDX core module provides a model representation of…7.5
- CVE-2025-64519TorrentPier is an open source BitTorrent Public/Private trac…8.8
- CVE-2025-6452A vulnerability was found in CodeAstro Patient Record Manage…4.8
- CVE-2025-64520GLPI is a free asset and IT management software package. Sta…4.3
Are you affected by CVE-2025-64515?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
