CVE-2025-3979
Published
CVSS v3
4.3
MEDIUM
CVSS v2
5
MEDIUM
Affected
1
PROJECT
Description
A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-ajax-1 of the component Password Change Handler. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.