A vulnerability was found in withstars Books-Management-System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /reader_delete.html. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
History

Mon, 12 May 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Withstars
Withstars books-management-system
CPEs cpe:2.3:a:withstars:books-management-system:1.0:*:*:*:*:*:*:*
Vendors & Products Withstars
Withstars books-management-system

Mon, 28 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 27 Apr 2025 04:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in withstars Books-Management-System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /reader_delete.html. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Title withstars Books-Management-System reader_delete.html cross-site request forgery
Weaknesses CWE-352
CWE-862
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-04-27T04:31:03.597Z

Updated: 2025-04-28T15:33:33.065Z

Reserved: 2025-04-26T07:03:26.551Z

Link: CVE-2025-3959

cve-icon Vulnrichment

Updated: 2025-04-28T15:33:28.445Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-27T05:15:14.913

Modified: 2025-05-12T19:24:31.943

Link: CVE-2025-3959

cve-icon Redhat

No data.