CVE-2025-13177 PUBLISHED

Bdtask/CodeCanyon SalesERP cross-site request forgery

Assigner: VulDB
Reserved: 14.11.2025 Published: 14.11.2025 Updated: 17.11.2025

A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor Bdtask
Product SalesERP
Versions
  • Version 20250728 is affected
Vendor CodeCanyon
Product SalesERP
Versions
  • Version 20250728 is affected

Credits

  • 4m3rr0r (VulDB User) reporter

References

Problem Types

  • Cross-Site Request Forgery CWE
  • Missing Authorization CWE