CVE-2025-12061 - CERT CVE
ID CVE-2025-12061
Sažetak The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users to import and execute arbitrary SQL statements
Reference
CVSS
Base: 8.6
Impact: 4.0
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH NONE NONE
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Zadnje važnije ažuriranje 26-11-2025 - 15:15
Objavljeno 26-11-2025 - 06:15