8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
Cross Site Request Forgery (CSRF) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to cause a denial of service via function handle_interface_POST_and_status.
AI Analysis
Cross Site Request Forgery (CSRF) vulnerability allowing remote attackers to cause a denial of service
Basic Information
ID
CVE-2025-65573
Source
mitre
Published
Dec 9, 2025 at 00:00
Modified
Dec 11, 2025 at 19:37
Affected Product
Vendor
AllskyTeam
Product
AllSky
Version
v2024.12.06_06
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
AllskyTeam
Product
AllSky
Version
v2024.12.06_06
References
- github.com /AllskyTeam/allsky
- github.com /AllskyTeam/allsky/blob/master/html/includes/functions.php
- github.com /AllskyTeam/allsky/blob/master/html/includes/dashboard_LAN.php
- github.com /AllskyTeam/allsky/blob/master/html/includes/dashboard_WLAN.php
- gh0stmezh.wordpress.com /2025/12/05/cve-2025-65573/