CVE-2019-25447 describes multiple Cross-Site Request Forgery (CSRF) vulnerabilities in OrientDB 3.0.17 GA Community Edition. Attackers can exploit these flaws, often in conjunction with reflected and stored Cross-Site Scripting (XSS), to perform unauthorized actions such as creating/deleting databases, modifying schemas, or managing users, due to a lack of token validation on authenticated requests. While the CVSS score is 4.3 (MEDIUM), indicating low impact on integrity and no impact on confidentiality or availability, the FAUCET Risk Score is 73/100. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.17CPE matchmatch criteria | cpe:2.3:a:orientdb:orientdb:3.0.17:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.