CVE Vulnerabilities

CVE-2025-6967

Execution After Redirect (EAR)

Published: Feb 10, 2026 | Modified: Feb 10, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authentication Bypass.This issue affects CMS: through 10022026.

NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Weakness

The web application sends a redirect to another location, but instead of exiting, it executes additional code.

References