CVE-2025-22347

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 352

Summary

CVE-2025-22347 is a Cross-Site Request Forgery (CSRF) vulnerability identified in BannerSky.com's BSK Forms Blacklist. This issue goes beyond a typical CSRF weakness, allowing an attacker to execute Blind SQL Injections. This vulnerability poses a significant risk, as it can be exploited to manipulate data in the affected system. The BSK Forms Blacklist is impacted from its inception through version 3.9, which means all users running these versions are vulnerable.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share