jerryshensjf JPACookieShop 蛋糕商城JPA版 AdminTypeCustController.java cross-site request forgery

CVE Details

Basic Information

Title jerryshensjf JPACookieShop 蛋糕商城JPA版 AdminTypeCustController.java cross-site request forgery
Type cve
Published 2025-07-27T05:02:05.371Z
Modified 2025-07-27T05:02:05.371Z

Product Information

Vendor jerryshensjf
Product JPACookieShop 蛋糕商城JPA版
Version 24a15c02b4f75042c9f7f615a3fed2ec1cefb999

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A medium-severity cross-site request forgery (CSRF) vulnerability was discovered in the JPACookieShop Cake Shop JPA Edition. This issue could allow remote attackers to perform unauthorized actions on behalf of authenticated users. The vulnerability affects the AdminTypeCustController.java file and has been publicly disclosed.
AI Severity Medium
AI Vendor jerryshensjf
AI Product JPACookieShop Cake Shop JPA Edition
AI Version 24a15c02b4f75042c9f7f615a3fed2ec1cefb999

Affected Products

  • jerryshensjf JPACookieShop 蛋糕商城JPA版 24a15c02b4f75042c9f7f615a3fed2ec1cefb999

Additional Information

CWE List CWE-352, CWE-862
Source VulDB

Description

A vulnerability, which was classified as problematic, was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f615a3fed2ec1cefb999. This affects an unknown part of the file AdminTypeCustController.java. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.