CVE-2025-6967
Deferred
Deferred - Pending Action
Execution After Redirect and JSON Hijacking in Sarman CMS
Publication date: 2026-02-10
Last updated on: 2026-06-05
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authentication Bypass.
This issue affects CMS: through 10022026.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sarman_soft | cms | to 10022026 (exc) |
| sarman_soft_software_and_technology_services_industry_and_trade_ltd_co | cms | to 10022026 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-698 | The web application sends a redirect to another location, but instead of exiting, it executes additional code. |