Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3092 | PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behalf. This includes GET and POST requests due to the missing SameSite= attribute on cookies and the ability to refresh cookies. Commit 14acb704891245bf1703ce6296d62112e85aa995 patches the issue. |
Wed, 07 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pwndoc Project
Pwndoc Project pwndoc |
|
| CPEs | cpe:2.3:a:pwndoc_project:pwndoc:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pwndoc Project
Pwndoc Project pwndoc |
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jan 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behalf. This includes GET and POST requests due to the missing SameSite= attribute on cookies and the ability to refresh cookies. Commit 14acb704891245bf1703ce6296d62112e85aa995 patches the issue. | |
| Title | Cross-Site Request Forgery (CSRF) allows creating admin account with POST request | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-12T20:41:20.188Z
Reserved: 2025-01-10T15:11:08.883Z
Link: CVE-2025-23044
Updated: 2025-02-12T20:32:35.450Z
Status : Analyzed
Published: 2025-01-20T16:15:28.170
Modified: 2025-05-07T18:59:21.327
Link: CVE-2025-23044
No data.
OpenCVE Enrichment
No data.
EUVD