CVE-2025-22347
CVSS 3.1 Score 8.2 of 10 (high)
Details
Published Jan 7, 2025
CWE ID 352
Summary
CVE-2025-22347 is a Cross-Site Request Forgery (CSRF) vulnerability identified in BannerSky.com's BSK Forms Blacklist. This issue goes beyond a typical CSRF weakness, allowing an attacker to execute Blind SQL Injections. This vulnerability poses a significant risk, as it can be exploited to manipulate data in the affected system. The BSK Forms Blacklist is impacted from its inception through version 3.9, which means all users running these versions are vulnerable.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.