CVE-2025-6967
8.7Sarman Soft Software · CMS
An Execution After Redirect (EAR) vulnerability in Sarman Soft Software CMS allows for JSON hijacking and authentication bypass.
Executive summary
A critical Execution After Redirect vulnerability in Sarman Soft Software CMS enables unauthenticated attackers to perform JSON hijacking and bypass authentication protocols.
Vulnerability
This vulnerability is a CWE-698 Execution After Redirect (EAR) flaw that allows an unauthenticated attacker to manipulate application flow, resulting in JSON hijacking and a complete authentication bypass.
Business impact
Successful exploitation of this vulnerability poses a severe risk to organizational data integrity and system access controls. By bypassing authentication, an attacker can gain unauthorized access to sensitive information stored within the CMS, potentially leading to total account takeover or data exfiltration. Given the CVSS score of 8.7, this issue is classified as high severity and requires immediate attention to prevent unauthorized administrative control.
Remediation
Immediate Action: Since the vendor has not responded to disclosure, administrators must restrict access to the affected CMS instance via network segmentation or by placing it behind a robust authentication proxy until a security patch is provided.
Proactive Monitoring: Monitor server access logs for unusual patterns of redirection or unauthorized JSON output requests that deviate from standard user traffic.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block abnormal redirect sequences and malicious JSON payloads directed at the application.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this authentication bypass necessitates an urgent review of all exposed Sarman Soft Software CMS instances. Because the vendor has been unresponsive, organizations should assume that no official patch will be forthcoming and should prioritize migrating to a more secure platform or implementing strict network-level access controls to isolate the vulnerable software from the public internet.
Sources
Originally found and disclosed by Çetin BİNİCİ, per the CVE Program record.