CVE-2025-22590
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-22590 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Prayer Times Anywhere from versions n/a through 2.0.1. An attacker can exploit this issue to inject and execute malicious scripts on a user's browser, by performing a CSRF attack and tricking the victim into making unintended requests. Additionally, Stored XSS (Cross-Site Scripting) is also present in the application, allowing the attacker to leave malicious scripts on the server, which can be executed on subsequent visits by the victim. This combination of CSRF and Stored XSS can lead to significant security risks, making it crucial for users to update their Prayer Times Anywhere installation to a secure version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.