Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain access to log information from the system by tricking an administrator into browsing a specifically crafted fake page of Kiteworks MFT. This issue has been patched in version 9.1.0.
Metrics
Affected Vendors & Products
References
History
Sat, 29 Nov 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain access to log information from the system by tricking an administrator into browsing a specifically crafted fake page of Kiteworks MFT. This issue has been patched in version 9.1.0. | |
| Title | Kiteworks MFT has a Cross-Site Request Forgery (CSRF) vulnerability | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-11-29T02:24:36.842Z
Updated: 2025-11-29T02:24:36.842Z
Reserved: 2025-07-11T19:05:23.825Z
Link: CVE-2025-53897
No data.
Status : Received
Published: 2025-11-29T03:15:58.653
Modified: 2025-11-29T03:15:58.653
Link: CVE-2025-53897
No data.
ReportizFlow