CVE-2025-6967
Last modified
CVE-2025-6967 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authentication Bypass. This issue affects CMS: through 10022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-6967?
How severe is CVE-2025-6967?
How do I fix CVE-2025-6967?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-69651GNU Binutils thru 2.46 readelf contains a vulnerability that…5.5
- CVE-2025-69652GNU Binutils thru 2.46 readelf contains a vulnerability that…6.2
- CVE-2025-69653A crafted JavaScript input can trigger an internal assertion…6.5
- CVE-2025-69654A crafted JavaScript input executed with the QuickJS release…7.5
- CVE-2025-6966NULL pointer dereference in TagSection.keys() in python-apt …5.5
- CVE-2025-69662SQL injection vulnerability in geopandas before v.1.1.2 allo…8.6
- CVE-2025-69674Buffer Overflow vulnerability in CDATA FD614GS3-R850 V3.2.7_…6.4
- CVE-2025-69689The Fan Control application V251 contains an improper privil…8.8
- CVE-2025-6969in OpenHarmony v5.1.0 and prior versions allow a local attac…5.5
- CVE-2025-69690Netgate pfSense CE 2.7.2 allows code execution by using the …9.1
- CVE-2025-69691Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC…9.9
- CVE-2025-69693Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decode…5.4
Are you affected by CVE-2025-6967?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
