CVE 8.6 HIGH

CSRF in FluxCP account endpoints allows account takeover / state-changing actions_CVE-2025-62797

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

FluxCP is a web-based Control Panel for rAthena servers written in PHP. A critical Cross-Site Request Forgery (CSRF) vulnerability exists in the FluxCP-based website template used by multiple rAthena/Ragnarok servers. State-changing POST endpoints accept browser-initiated requests that are authorized solely by the session cookie without per-request anti-CSRF tokens or robust Origin/Referer validation. An attacker who can lure a logged-in user to an attacker-controlled page can cause that user to perform sensitive actions without their intent. This vulnerability is fixed with commit e3f130c.

AI Analysis

A Cross-Site Request Forgery (CSRF) vulnerability exists in FluxCP, allowing an attacker to perform sensitive actions on behalf of a logged-in user.

Basic Information

ID CVE-2025-62797
Source GitHub_M
Published Oct 29, 2025 at 17:49
Modified Oct 29, 2025 at 19:01

Affected Product

Vendor rathena
Product FluxCP
Version < e3f130c4a2ccd615a3ee2ee0302ecbfbd84747e6
Affected Versions rathena FluxCP < e3f130c4a2ccd615a3ee2ee0302ecbfbd84747e6

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor rathena
Product FluxCP
Version < e3f130c4a2ccd615a3ee2ee0302ecbfbd84747e6

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.