Skip to main content
Vulnerability Database/CVE-2025-64515

CVE-2025-64515: Open Forms Auth Bypass Vulnerability

CVE-2025-64515 is an authentication bypass flaw in Maykinmedia Open Forms that allows malicious users to modify readonly prefill data fields. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2025-64515 Overview

CVE-2025-64515 affects Maykinmedia Open Forms, a platform that lets organizations create and publish smart web forms. The vulnerability allows authenticated users to bypass client-side readonly or disabled attributes on prefill data fields. Attackers can modify form values that the application intended to lock, altering data they are not authorized to change. The flaw is tracked under CWE-20: Improper Input Validation and is addressed in Open Forms versions 3.2.7 and 3.3.3.

Critical Impact

Authenticated users can tamper with prefilled form data that was presented as read-only, undermining data integrity for submissions that depend on trusted prefill values.

Affected Products

  • Maykinmedia Open Forms versions prior to 3.2.7 on the 3.2.x branch
  • Maykinmedia Open Forms versions prior to 3.3.3 on the 3.3.x branch
  • Deployments using dynamically applied readonly or disabled prefill fields

Discovery Timeline

  • 2025-11-18 - CVE-2025-64515 published to NVD
  • 2025-11-18 - Open Forms 3.2.7 and 3.3.3 released with the fix
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-64515

Vulnerability Analysis

Open Forms supports prefill functionality that populates form fields with data retrieved from backend sources. Form designers can mark these prefilled fields as readonly or disabled so end users cannot modify the prepopulated values. The server-side submission handler failed to re-validate that fields marked readonly in the form configuration retained their original prefill values. A malicious authenticated user who intercepts or crafts the HTTP submission can replace these values with arbitrary input. Legitimate users interacting through the standard browser interface see no change in behavior, since the restriction remains enforced in the user interface layer.

Root Cause

The root cause is improper input validation on form submission ([CWE-20]). The application enforced the readonly or disabled state only in the frontend rendering logic. The backend accepted submitted field values without comparing them against the authoritative prefill data retrieved server-side. This gap between client-presented restrictions and server-side validation enables trusted-value tampering.

Attack Vector

Exploitation requires network access to the Open Forms application and valid user authentication. An attacker submits a crafted HTTP request to the form submission endpoint, substituting the server-trusted prefill values with attacker-chosen content. No elevated privileges, user interaction, or complex preconditions are required beyond holding a valid session on a vulnerable instance. See the GitHub Security Advisory GHSA-cp63-63mq-5wvf for additional detail.

Detection Methods for CVE-2025-64515

Indicators of Compromise

  • Form submissions where prefill-sourced field values differ from the values returned by the configured prefill plugin for the submitting user.
  • Submissions originating from non-browser clients or automation tools against endpoints that normally receive browser traffic.
  • Audit log entries showing field changes on components configured with the readonly or disabled property.

Detection Strategies

  • Compare submitted field values to the prefill source of record after submission and flag deltas on fields that are configured as readonly.
  • Instrument server-side logging to record the original prefill payload alongside the final submitted payload for each form instance.
  • Review historical submissions on forms using sensitive prefill data such as identity attributes, case references, or financial amounts.

Monitoring Recommendations

  • Enable verbose submission logging on all Open Forms deployments running affected versions until patching completes.
  • Alert on repeated submissions from the same account that modify readonly fields across multiple forms.
  • Correlate web server access logs with application submission events to identify replayed or manipulated POST requests.

How to Mitigate CVE-2025-64515

Immediate Actions Required

  • Upgrade Open Forms to version 3.2.7 or 3.3.3 depending on the branch in use.
  • Audit submissions received since prefill-with-readonly fields were introduced in affected deployments.
  • Rotate or revalidate any downstream records that were populated from potentially tampered submissions.

Patch Information

Maykinmedia released fixes in Open Forms 3.2.7 and 3.3.3 on 2025-11-18. Release notes are available in the Open Forms Changelog 3.2.7 and the Open Forms Changelog 3.3.3. The patched versions enforce server-side validation that prefilled readonly fields retain their original values before accepting a submission.

Workarounds

  • Avoid configuring prefill fields with the readonly or disabled attribute as a trust boundary until the patch is applied.
  • Restrict access to Open Forms instances to trusted authenticated users through network controls or reverse proxy authentication during the remediation window.
  • Implement downstream validation in integrated systems that independently verifies values received from Open Forms against authoritative sources.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.