nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-6967 CVE-2025-6967
HIGH
Authentication Bypass in Sarman Soft's CMS
Record summary
CVE-2025-6967 has a selected CVSS score of 8.7 (high).
Description
Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authentication Bypass. This issue affects CMS: through 10022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | Through 10022026 | affected |
References
3siberguvenlik.gov.trGovernment resource
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0050 usom.gov.trGovernment resourcebroken link
https://www.usom.gov.tr/bildirim/tr-26-0050