VYPR
Medium severityNVD Advisory· Published May 23, 2025· Updated Apr 15, 2026

CVE-2025-48740

CVE-2025-48740

Description

A Cross-Site Request Forgery (CSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows a remote attacker to trigger requests on their victim's behalf, if the attacker lures a privileged user, authenticated with basic authentication.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-Site Request Forgery in TheHive allows an attacker to execute privileged actions on behalf of an authenticated user via basic authentication.

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in TheHive versions prior to 5.2.16, 5.3.11, 5.4.10, and 5.5.1 when basic authentication is enabled. The application fails to implement anti-CSRF tokens or other protections, allowing an attacker to craft malicious requests that are executed in the context of a legitimate user's session.

Exploitation

An unauthenticated remote attacker can exploit this by luring a privileged user, who is authenticated via basic authentication, into visiting a crafted webpage. The attacker can then forge requests to perform actions such as changing the victim's password or escalating privileges, without the victim's knowledge.

Impact

Successful exploitation enables an attacker to perform sensitive operations on behalf of the victim, potentially leading to privilege escalation or account compromise. The CVSS v4.0 base score is 5.9 (Medium), with high impact on integrity and no impact on confidentiality.

Mitigation

The issue is fixed in TheHive versions 5.2.16, 5.3.11, 5.4.10, and 5.5.1. Users are advised to upgrade to a patched version. No workarounds are documented [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.