CVE-2025-9747 | Koillection up to 1.6.18 csrf_protection_controller.js cross-site request forgery (Issue 1393 / EUVD-2025-26312)
A vulnerability was found in Koillection up to 1.6.18 and classified as problematic. Affected is an unknown function of the file assets/controllers/csrf_protection_controller.js. Such manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2025-9747. The attack can be executed remotely. Additionally, an exploit exists.
It is suggested to upgrade the affected component.
The vendor explains: "I ended up switching to a newer CSRF handling using stateless token."