Home

Description

EN DE

A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component API Endpoint. Such manipulation leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is beb153ce52dceb971c1518f98333328c95f1ba20. It is best practice to apply a patch to resolve this issue.

In JhumanJ OpnForm up to 1.9.3 ist eine Schwachstelle entdeckt worden. Betroffen hiervon ist ein unbekannter Ablauf der Datei /custom-domains der Komponente API Endpoint. Die Bearbeitung verursacht missing authorization. Der Angriff kann remote ausgeführt werden. Der Exploit steht zur öffentlichen Verfügung. Der Name des Patches ist beb153ce52dceb971c1518f98333328c95f1ba20. Als bestmögliche Massnahme wird Patching empfohlen.

PUBLISHED Reserved 2025-10-07 | Published 2025-10-08 | Updated 2025-10-08 | Assigner VulDB




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
MEDIUM: 6.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
MEDIUM: 6.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
6.5AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C

Problem types

Missing Authorization

Incorrect Authorization

Product status

1.9.0
affected

1.9.1
affected

1.9.2
affected

1.9.3
affected

Timeline

2025-10-07:Advisory disclosed
2025-10-07:VulDB entry created
2025-10-07:VulDB entry last update

Credits

balejin (VulDB User) reporter

References

vuldb.com/?id.327375 (VDB-327375 | JhumanJ OpnForm API Endpoint custom-domains authorization) vdb-entry

vuldb.com/?ctiid.327375 (VDB-327375 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.666879 (Submit #666879 | GitHub OpnForm 1.9.3 Improper Access Controls) third-party-advisory

docs.google.com/...v6ySsbCIhVynf8_djardLZYEDOe0/edit?tab=t.0 exploit

github.com/...mmits/beb153ce52dceb971c1518f98333328c95f1ba20 issue-tracking patch

cve.org (CVE-2025-11438)

nvd.nist.gov (CVE-2025-11438)

Download JSON