CVE-2025-23044

MEDIUM

pwndoc < 0.9.0 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behalf. This includes GET and POST requests due to the missing SameSite= attribute on cookies and the ability to refresh cookies. Commit 14acb704891245bf1703ce6296d62112e85aa995 patches the issue.

Scores

CVSS v3 6.8
EPSS 0.0024
EPSS Percentile 14.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (1)
pwndoc_project/pwndoc < 0.9.0
Published Jan 20, 2025
Tracked Since Feb 18, 2026