Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 05 Mar 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:orientdb:orientdb:3.1.0:-:*:*:*:*:*:* |
Tue, 24 Feb 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:orientdb:orientdb:3.0.17:*:*:*:*:*:*:* |
Tue, 24 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Orientdb
Orientdb orientdb |
|
| Vendors & Products |
Orientdb
Orientdb orientdb |
Fri, 20 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OrientDB 3.0.17 GA Community Edition contains cross-site request forgery vulnerabilities that allow attackers to perform unauthorized actions by crafting malicious requests to endpoints like /database/, /command/, and /document/. Attackers can create or delete databases, modify schema classes, manage users, and create functions by sending authenticated requests without token validation, combined with reflected and stored cross-site scripting vulnerabilities in the web interface. | |
| Title | OrientDB 3.0.17 Cross-Site Request Forgery | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:04:10.020Z
Reserved: 2026-02-20T18:25:36.023Z
Link: CVE-2019-25447
Updated: 2026-02-24T15:35:12.653Z
Status : Analyzed
Published: 2026-02-20T23:16:01.173
Modified: 2026-02-24T16:42:59.007
Link: CVE-2019-25447
No data.
OpenCVE Enrichment
Updated: 2026-02-23T14:33:17Z