The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete all notifications via the /notifications/delete/ URI.
Metrics
Affected Vendors & Products
References
History
Wed, 27 Aug 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Bevy
Bevy event Service |
|
Vendors & Products |
Bevy
Bevy event Service |
Wed, 27 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-352 | |
Metrics |
cvssV3_1
|
Wed, 27 Aug 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 27 Aug 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete all notifications via the /notifications/delete/ URI. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-08-27T00:00:00.000Z
Updated: 2025-08-27T18:51:20.671Z
Reserved: 2025-07-27T00:00:00.000Z
Link: CVE-2025-54598

Updated: 2025-08-27T17:09:02.867Z

Status : Received
Published: 2025-08-27T16:15:36.390
Modified: 2025-08-27T19:15:37.183
Link: CVE-2025-54598

No data.