Skip to main content
Loading…
    CVE-2025-60645 — A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request. — CVE Database · The Intelligence Room