Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23564 | A vulnerability classified as critical was found in cloudfavorites favorites-web up to 1.3.0. Affected by this vulnerability is the function getCollectLogoUrl of the file app/src/main/java/com/favorites/web/CollectController.java. The manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
Tue, 05 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Favorites-web Project
Favorites-web Project favorites-web |
|
| Vendors & Products |
Favorites-web Project
Favorites-web Project favorites-web |
Mon, 04 Aug 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as critical was found in cloudfavorites favorites-web up to 1.3.0. Affected by this vulnerability is the function getCollectLogoUrl of the file app/src/main/java/com/favorites/web/CollectController.java. The manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | cloudfavorites favorites-web CollectController.java getCollectLogoUrl server-side request forgery | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-05T13:18:48.609Z
Reserved: 2025-08-04T06:51:30.565Z
Link: CVE-2025-8529
Updated: 2025-08-05T13:18:40.323Z
Status : Deferred
Published: 2025-08-04T23:15:28.560
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-8529
No data.
OpenCVE Enrichment
Updated: 2025-08-05T11:38:53Z
EUVD