Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-29722. PoCs published by cypherdavy.
AI-analyzed exploit summary This repository contains a detailed writeup and proof-of-concept for CVE-2025-29722, a CSRF vulnerability in Commercify v1.0. The PoC demonstrates how an attacker can craft malicious requests to modify user data due to the lack of CSRF protection mechanisms.
Description
A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.
Exploits (1)
This repository contains a detailed writeup and proof-of-concept for CVE-2025-29722, a CSRF vulnerability in Commercify v1.0. The PoC demonstrates how an attacker can craft malicious requests to modify user data due to the lack of CSRF protection mechanisms.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L