CVE-2025-60535
the affected product
A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to execute arbitrary operations via a crafted GET request.
- CVSS
- 7.3
- EPSS
- 0.14% 3.98% percentile
- CISA KEV
- Not listed
- Published
- 2025.10.15