OpenPLC_V3 is vulnerable to a cross-site request forgery ...
High severity
Unreviewed
Published
Dec 13, 2025
to the GitHub Advisory Database
•
Updated Dec 13, 2025
Description
Published by the National Vulnerability Database
Dec 13, 2025
Published to the GitHub Advisory Database
Dec 13, 2025
Last updated
Dec 13, 2025
OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack
due to the absence of proper CSRF validation. This issue allows an
unauthenticated attacker to trick a logged-in administrator into
visiting a maliciously crafted link, potentially enabling unauthorized
modification of PLC settings or the upload of malicious programs which
could lead to significant disruption or damage to connected systems.
References