PoC Index

CVE-2025-29722

MEDIUM 6.3EPSS 0.2%

A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.

CVSS v3.1
6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
EPSS
0.18% chance of exploitation in the next 30 days, 8th percentile
Published
2025-04-17

Proof-of-concept exploits (1)

References

Related