CVE-2025-61547 Details
Description
Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.76). The application does not implement proper CSRF tokens or other other protective measures, allowing a remote attacker to trick authenticated users into unknowingly executing unintended actions within their session. This can lead to unauthorized data modification such as credential updates.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in edu Business Solutions Print Shop Pro WebDesk version 18.34. This vulnerability allows remote attackers to trick authenticated users into performing unintended actions within their sessions, as the application lacks proper CSRF token implementation and other protective measures. Exploitation of this vulnerability could lead to unauthorized data modifications, such as changes to user credentials.
To address this vulnerability, implement anti-CSRF tokens for all state-changing requests and apply the SameSite=Strict attribute to session cookies. Additionally, validate Origin and Referer headers on sensitive endpoints to block unauthorized cross-origin requests. For high-risk actions like credential modifications, consider enforcing additional safeguards such as step-up authentication, CAPTCHA, or confirmation via the user's primary contact method.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/chndlrx/vulnerability-disclosures/tree/main/CVE-2025-61547 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| edubusinesssolutions print shop pro webdesk | 18.34 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 10, 2026 | CVE Modified | [email protected] |
| Jan 22, 2026 | Initial Analysis | [email protected] |
| Jan 8, 2026 | CVE Modified | CISA-ADP |
| Jan 8, 2026 | New CVE Received | [email protected] |