CVE-2025-5132 Details
Description
A vulnerability was found in Tmall Demo up to 20250505. It has been rated as problematic. This issue affects some unknown processing of the file tmall/admin/account/logout. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
A cross-site request forgery (CSRF) vulnerability has been identified in Tmall Demo versions prior to 20250505. This issue arises from an unknown processing flaw in the file tmall/admin/account/logout, allowing remote attackers to exploit the login status of users and perform unauthorized actions. Such CSRF attacks could lead to serious consequences, including the leakage of user information, unauthorized tampering with accounts, or the accidental triggering of sensitive operations.
To address this CSRF vulnerability, it is recommended to implement measures such as verifying the source of requests using the Referer or Origin headers, utilizing CSRF tokens, setting the SameSite attribute for cookies, and requiring additional authentication for sensitive operations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bdkuzma/vuln/issues/11 | CISA-ADP | ExploitIssue TrackingThird Party Advisory |
| https://github.com/bdkuzma/vuln/issues/11 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://vuldb.com/?ctiid.310211 | [email protected] | Permissions Required |
| https://vuldb.com/?id.310211 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.571924 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| project team tmall demo | <= 2025-05-05 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2025 | Initial Analysis | [email protected] |
| May 28, 2025 | CVE Modified | CISA-ADP |
| May 24, 2025 | New CVE Received | [email protected] |