CVE-2025-6967Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authentication Bypass. This issue affects CMS: through 10022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-698

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-02-10); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-10: 4Mentions · 2026-02-11: 1Technical Details · 2026-02-10: 402-1002-11
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-104
Disclosure3General1
2026-02-111
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-6967 Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijac… https://www.cve.org/CVERecord?id=CVE-2025-6967

    Post summary

    The post announces CVE‑2025‑6967, an EAR vulnerability in Sarman Soft CMS that enables JSON hijacking.

    00020379
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-6967 Execution After Redirect Vulnerability in Sarman Soft CMS with JSON Hijacking https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-6967

    Post summary

    The text only references CVE‑2025‑6967 with a brief title and a link, offering minimal technical detail and no actionable exploit or mitigation information.

    0001045
    4.0K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2025-6967 - Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. - CMS - https://www.redpacketsecurity.com/cve-alert-cve-2025-6967-sarman-soft-software-and-technology-services-industry-and-trade-ltd-co-cms/ #OSINT #ThreatIntel #CyberSecurity #cve-2025-6967 #sarman-soft-software-and-technology-services-industry-and-trade-ltd-co #cms

    Post summary

    The tweet announces a CVE alert for CVE-2025-6967 affecting Sarman Soft Software’s CMS and provides a link to a Red Packet Security alert page.

    00000101
    3.5K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-6967: HIGH] Sarman Soft CMS vulnerability exposes JSON Hijacking, Authentication Bypass due to Execution After Redirect flaw. Issue affects CMS: through 10022026.#cve,CVE-2025-6967,#cybersecurity https://cvefind.com/CVE-2025-6967

    Post summary

    The post announces a high‑severity CVE‑2025‑6967 affecting Sarman Soft CMS that permits JSON hijacking and authentication bypass via execution after redirect; no PoC, exploit, patch, or active exploitation details are provided.

    0000045
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-6967 - High Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authentication By... https://www.thehackerwire.com/vulnerability/CVE-2025-6967/ https://t.co/mX4Pd0DbNI

    Post summary

    The tweet discloses CVE‑2025‑6967 as an Execution After Redirect flaw that permits JSON hijacking, without indicating patches or active exploitation.

    0000074
    112 followersView on X

Explore more