VDB
CVE-2025-3979
CVE-2025-3979
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-ajax-1 of the component Password Change Handler. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
EPSS 0.14% · 34.3th percentile
Risk Scores
CVSS 4.0
5.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.14%
34.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| lecms | lecms | 3.0.3 |
| dazhouda | lecms | 3.0.3 |
Exploit Intelligence
- CIRCL seen: CVE-2025-3979 (circl-sighting)
- CIRCL seen: CVE-2025-3979 (circl-sighting)
- VDB-306315 | dazhouda lecms Password Change index.php cross-site request forgery (circl)
- VDB-306315 | CTI Indicators (IOB, IOC, IOA) (circl)
- Submit #557787 | https://gitee.com/dazhouda/lecms3.0.3 lecms 3.0.3 Cross-Site Request Forgery (circl)
- https://github.com/dtwin88/cve-md/blob/main/lecms%20V3.0.3/lecms_3.md (cve.org)
- EUVD-2025-12436.json (github-poc)
- EUVD-2025-12436.json (github-poc)
- EUVD-2025-12436.json (github-poc)
- EUVD-2025-12436.json (github-poc)
…and 1 more exploits
Timeline
- Apr 27, 2025 CVE Published
- Apr 27, 2025 PoC Published
- Apr 27, 2025 PoC Published
- Apr 28, 2025 EPSS Score
- Apr 28, 2025 CVE Updated
- May 10, 2025 EPSS Score
- May 22, 2025 EPSS Score
- May 25, 2025 Coalition ESS Score
- Jun 3, 2025 EPSS Score
- Jun 15, 2025 EPSS Score
- Jun 27, 2025 EPSS Score
- Jul 9, 2025 EPSS Score
References
- VDB-306315 | dazhouda lecms Password Change index.php cross-site request forgery vdb
- VDB-306315 | CTI Indicators (IOB, IOC, IOA) url
- Submit #557787 | https://gitee.com/dazhouda/lecms3.0.3 lecms 3.0.3 Cross-Site Request Forgery third-party-advisory
- https://github.com/dtwin88/cve-md/blob/main/lecms%20V3.0.3/lecms_3.md exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-3979 advisory