cleantalk
Vulnerabilities and Security Researches

Members page only for logged in users, CVE-2025-28901

CVE, Research URL

CVE-2025-28901

Published on
Mar 12, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Naren Members page only for logged in users allows Stored XSS. This issue affects Members page only for logged in users: from n/a through 1.4.2.
Affected versions
Min -, max 1.4.2.
Status
vulnerable