A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Mon, 17 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 15 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Bdtask
Bdtask saleserp
Codecanyon
Codecanyon saleserp
Vendors & Products Bdtask
Bdtask saleserp
Codecanyon
Codecanyon saleserp

Fri, 14 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Bdtask/CodeCanyon SalesERP cross-site request forgery
Weaknesses CWE-352
CWE-862
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-11-14T19:02:07.421Z

Updated: 2025-11-17T20:41:11.611Z

Reserved: 2025-11-14T11:01:37.829Z

Link: CVE-2025-13177

cve-icon Vulnrichment

Updated: 2025-11-17T20:41:01.956Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-14T19:15:57.977

Modified: 2025-11-18T14:06:55.963

Link: CVE-2025-13177

cve-icon Redhat

No data.