CVE-2025-11439

A vulnerability was found in JhumanJ OpnForm up to 1.9.3. This issue affects some unknown processing of the file /show/integrations. Performing manipulation results in missing authorization. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The patch is named 11d97d78f2de2cb49f79baed6bde8b611ec1f384. It is recommended to apply a patch to fix this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jhumanj:opnform:*:*:*:*:*:*:*:*

History

09 Oct 2025, 16:18

Type Values Removed Values Added
References () https://docs.google.com/document/d/1GUjJA9vUbsXUngAv6ySsbCIhVynf8_djardLZYEDOe0/edit?tab=t.0#heading=h.reuyi9lwvpj - () https://docs.google.com/document/d/1GUjJA9vUbsXUngAv6ySsbCIhVynf8_djardLZYEDOe0/edit?tab=t.0#heading=h.reuyi9lwvpj - Exploit, Third Party Advisory
References () https://github.com/JhumanJ/OpnForm/pull/900/commits/11d97d78f2de2cb49f79baed6bde8b611ec1f384 - () https://github.com/JhumanJ/OpnForm/pull/900/commits/11d97d78f2de2cb49f79baed6bde8b611ec1f384 - Patch
References () https://vuldb.com/?ctiid.327376 - () https://vuldb.com/?ctiid.327376 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.327376 - () https://vuldb.com/?id.327376 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.666880 - () https://vuldb.com/?submit.666880 - Third Party Advisory, VDB Entry
First Time Jhumanj
Jhumanj opnform
CPE cpe:2.3:a:jhumanj:opnform:*:*:*:*:*:*:*:*

08 Oct 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-08 07:15

Updated : 2025-10-09 16:18


NVD link : CVE-2025-11439

Mitre link : CVE-2025-11439

CVE.ORG link : CVE-2025-11439


JSON object : View

Products Affected

jhumanj

  • opnform
CWE
CWE-862

Missing Authorization

CWE-863

Incorrect Authorization