CVE-2025-58469

HIGH

QuLog Center 1.8.0.872-1.8.2.923 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: QuLog Center 1.8.2.927 ( 2025/09/17 ) and later

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0005
EPSS Percentile 15.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
qnap/qulog_center 1.8.0.872 - 1.8.2.923
Published Nov 07, 2025
Tracked Since Feb 18, 2026