CVE-2025-34133 Details
Description
Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF) vulnerability in its API. The API accepts any authenticated request that contains a JSON field named 'csrf_token' without validating the field’s value; only the presence of the field is checked. An attacker can craft a cross-site request that causes a logged-in victim’s browser to submit a JSON POST containing an arbitrary or empty 'csrf_token', and the API will execute the request with the victim’s privileges. Successful exploitation can allow an attacker to perform privileged actions as the victim potentially resulting in account takeover, privilege escalation, or service disruption.
A cross-site request forgery (CSRF) vulnerability has been identified in the Wimi Teamwork API, affecting versions prior to 7.38.17. The vulnerability arises because the API accepts authenticated requests with a 'csrf_token' JSON field without validating its content, only checking for the field's presence. This flaw allows an attacker to craft a request that exploits the victim's privileges by submitting an arbitrary or empty 'csrf_token'. Successful exploitation could lead to account takeover, privilege escalation, or service disruption.
Users are advised to update to Wimi Teamwork version 7.38.17 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 27, 2025CISA-ADP
Assessed Oct 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.vulncheck.com/advisories/wimi-teamwork-csrf | [email protected] | Advisory |
| https://www.wimi-teamwork.com/ | [email protected] | Vendor |
| https://www.wimi-teamwork.com/product-news/release-7-38/ | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Wimi Teamwork | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 27, 2025 | New CVE Received | [email protected] |
Volerion