CVE-2025-11022 PUBLISHED

CSRF in Panilux

Assigner: TR-CERT
Reserved: 26.09.2025 Published: 09.12.2025 Updated: 09.12.2025

Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery. 

This

CSRF vulnerability resulting in Command Injection has been identified.

This issue affects Panilux: before v.0.10.0. NOTE: The vendor was contacted and responded that they deny ownership of the mentioned product.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS Score: 9.6

Product Status

Vendor Personal Project
Product Panilux
Versions Default: unaffected
  • affected from 0 to v.0.10.0 (excl.)

Credits

  • Ahmet Ümit BAYRAM finder

References

Problem Types

  • CWE-352 Cross-Site Request Forgery (CSRF) CWE

Impacts

  • CAPEC-62 Cross Site Request Forgery