CVE-2025-64515 Overview
CVE-2025-64515 affects Maykinmedia Open Forms, a platform that lets organizations create and publish smart web forms. The vulnerability allows authenticated users to bypass client-side readonly or disabled attributes on prefill data fields. Attackers can modify form values that the application intended to lock, altering data they are not authorized to change. The flaw is tracked under CWE-20: Improper Input Validation and is addressed in Open Forms versions 3.2.7 and 3.3.3.
Critical Impact
Authenticated users can tamper with prefilled form data that was presented as read-only, undermining data integrity for submissions that depend on trusted prefill values.
Affected Products
- Maykinmedia Open Forms versions prior to 3.2.7 on the 3.2.x branch
- Maykinmedia Open Forms versions prior to 3.3.3 on the 3.3.x branch
- Deployments using dynamically applied readonly or disabled prefill fields
Discovery Timeline
- 2025-11-18 - CVE-2025-64515 published to NVD
- 2025-11-18 - Open Forms 3.2.7 and 3.3.3 released with the fix
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-64515
Vulnerability Analysis
Open Forms supports prefill functionality that populates form fields with data retrieved from backend sources. Form designers can mark these prefilled fields as readonly or disabled so end users cannot modify the prepopulated values. The server-side submission handler failed to re-validate that fields marked readonly in the form configuration retained their original prefill values. A malicious authenticated user who intercepts or crafts the HTTP submission can replace these values with arbitrary input. Legitimate users interacting through the standard browser interface see no change in behavior, since the restriction remains enforced in the user interface layer.
Root Cause
The root cause is improper input validation on form submission ([CWE-20]). The application enforced the readonly or disabled state only in the frontend rendering logic. The backend accepted submitted field values without comparing them against the authoritative prefill data retrieved server-side. This gap between client-presented restrictions and server-side validation enables trusted-value tampering.
Attack Vector
Exploitation requires network access to the Open Forms application and valid user authentication. An attacker submits a crafted HTTP request to the form submission endpoint, substituting the server-trusted prefill values with attacker-chosen content. No elevated privileges, user interaction, or complex preconditions are required beyond holding a valid session on a vulnerable instance. See the GitHub Security Advisory GHSA-cp63-63mq-5wvf for additional detail.
Detection Methods for CVE-2025-64515
Indicators of Compromise
- Form submissions where prefill-sourced field values differ from the values returned by the configured prefill plugin for the submitting user.
- Submissions originating from non-browser clients or automation tools against endpoints that normally receive browser traffic.
- Audit log entries showing field changes on components configured with the readonly or disabled property.
Detection Strategies
- Compare submitted field values to the prefill source of record after submission and flag deltas on fields that are configured as readonly.
- Instrument server-side logging to record the original prefill payload alongside the final submitted payload for each form instance.
- Review historical submissions on forms using sensitive prefill data such as identity attributes, case references, or financial amounts.
Monitoring Recommendations
- Enable verbose submission logging on all Open Forms deployments running affected versions until patching completes.
- Alert on repeated submissions from the same account that modify readonly fields across multiple forms.
- Correlate web server access logs with application submission events to identify replayed or manipulated POST requests.
How to Mitigate CVE-2025-64515
Immediate Actions Required
- Upgrade Open Forms to version 3.2.7 or 3.3.3 depending on the branch in use.
- Audit submissions received since prefill-with-readonly fields were introduced in affected deployments.
- Rotate or revalidate any downstream records that were populated from potentially tampered submissions.
Patch Information
Maykinmedia released fixes in Open Forms 3.2.7 and 3.3.3 on 2025-11-18. Release notes are available in the Open Forms Changelog 3.2.7 and the Open Forms Changelog 3.3.3. The patched versions enforce server-side validation that prefilled readonly fields retain their original values before accepting a submission.
Workarounds
- Avoid configuring prefill fields with the readonly or disabled attribute as a trust boundary until the patch is applied.
- Restrict access to Open Forms instances to trusted authenticated users through network controls or reverse proxy authentication during the remediation window.
- Implement downstream validation in integrated systems that independently verifies values received from Open Forms against authoritative sources.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.