A vulnerability was found in JhumanJ OpnForm up to 1.9.3. This issue affects some unknown processing of the file /show/integrations. Performing manipulation results in missing authorization. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The patch is named 11d97d78f2de2cb49f79baed6bde8b611ec1f384. It is recommended to apply a patch to fix this issue.
References
Link | Resource |
---|---|
https://docs.google.com/document/d/1GUjJA9vUbsXUngAv6ySsbCIhVynf8_djardLZYEDOe0/edit?tab=t.0#heading=h.reuyi9lwvpj | Exploit Third Party Advisory |
https://github.com/JhumanJ/OpnForm/pull/900/commits/11d97d78f2de2cb49f79baed6bde8b611ec1f384 | Patch |
https://vuldb.com/?ctiid.327376 | Permissions Required VDB Entry |
https://vuldb.com/?id.327376 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.666880 | Third Party Advisory VDB Entry |
Configurations
History
09 Oct 2025, 16:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.google.com/document/d/1GUjJA9vUbsXUngAv6ySsbCIhVynf8_djardLZYEDOe0/edit?tab=t.0#heading=h.reuyi9lwvpj - Exploit, Third Party Advisory | |
References | () https://github.com/JhumanJ/OpnForm/pull/900/commits/11d97d78f2de2cb49f79baed6bde8b611ec1f384 - Patch | |
References | () https://vuldb.com/?ctiid.327376 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.327376 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.666880 - Third Party Advisory, VDB Entry | |
First Time |
Jhumanj
Jhumanj opnform |
|
CPE | cpe:2.3:a:jhumanj:opnform:*:*:*:*:*:*:*:* |
08 Oct 2025, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-08 07:15
Updated : 2025-10-09 16:18
NVD link : CVE-2025-11439
Mitre link : CVE-2025-11439
CVE.ORG link : CVE-2025-11439
JSON object : View
Products Affected
jhumanj
- opnform