CVE-2025-22590

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 352

Summary

CVE-2025-22590 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Prayer Times Anywhere from versions n/a through 2.0.1. An attacker can exploit this issue to inject and execute malicious scripts on a user's browser, by performing a CSRF attack and tricking the victim into making unintended requests. Additionally, Stored XSS (Cross-Site Scripting) is also present in the application, allowing the attacker to leave malicious scripts on the server, which can be executed on subsequent visits by the victim. This combination of CSRF and Stored XSS can lead to significant security risks, making it crucial for users to update their Prayer Times Anywhere installation to a secure version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share