CVE-2018-25186: TINA4 Stack

Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credentials by submitting forged POST requests to the profile endpoint. Attackers can craft HTML forms targeting the /kim/profile endpoint with hidden fields containing malicious user data like passwords and email addresses to update administrator accounts without authentication.

Affected products

  • TINA4 TINA4 Stack: version 1.0.3 only

Published 2026-03-06. Last modified 2026-06-17.