CVE-2025-48497: Irohasoft Iroha Board
Medium severity, CVSS 5.1. EPSS: 0.1% chance of exploitation in the next 30 days.
Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a specially crafted URL while being logged in to the affected product, arbitrary learning histories may be registered.
Affected products
- Irohasoft Iroha Board: before 0.10.13 (fixed in 0.10.13)
Published 2025-06-26. Last modified 2026-06-17.