CVE-2025-28062
HIGHERPNEXT 14.82.1 and 14.74.3 - Cross-Site Request Forgery
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2025-28062. PoCs published by Ahmed Thaiban, Thvt0ne.
AI-analyzed exploit summary The exploit demonstrates a CSRF vulnerability in ERPNext versions <= 14.82.1 and 14.74.3, allowing account takeover via unauthorized state-changing operations such as user deletion, role assignment, and password reset. The PoC includes functional HTML snippets targeting specific API endpoints without CSRF protection.
Description
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.
Exploits (2)
The exploit demonstrates a CSRF vulnerability in ERPNext versions <= 14.82.1 and 14.74.3, allowing account takeover via unauthorized state-changing operations such as user deletion, role assignment, and password reset. The PoC includes functional HTML snippets targeting specific API endpoints without CSRF protection.
This repository contains a working proof-of-concept for CVE-2025-28062, demonstrating CSRF vulnerabilities in ERPNext versions 14.82.1 and 14.74.3 that allow account takeover, user deletion, and privilege escalation.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N