CVE-2025-3997
MEDIUMdazhouda lecms 3.0.3 - CSRF
Title source: llmDescription
A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-profile-ajax-1 of the component Personal Information Page. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Scores
CVSS v3
4.3
EPSS
0.0008
EPSS Percentile
23.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Classification
CWE
CWE-862
CWE-352
Status
draft
Timeline
Published
Apr 28, 2025
Tracked Since
Feb 18, 2026