CVE-2025-5185

MEDIUM

Summer Pearl Group Vacation Rental Management Platform <1.0.1 - CSRF

Title source: llm
STIX 2.1

Description

A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. Upgrading to version 1.0.2 is able to address this issue. It is recommended to upgrade the affected component.

References (3)

Core 3
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.310273
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.310273

Scores

CVSS v3 4.3
EPSS 0.0019
EPSS Percentile 9.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352 CWE-862
Status published
Products (2)
Summer Pearl Group/Vacation Rental Management Platform 1.0.0
Summer Pearl Group/Vacation Rental Management Platform 1.0.1
Published May 26, 2025
Tracked Since Feb 18, 2026