CVE-2025-23044
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Published Jan 20, 2025
CWE ID 352
Summary
CVE-2025-23044 is a vulnerability affecting PwnDoc, a penetration test report generator. The issue stems from the lack of Cross-Site Request Forgery (CSRF) protection, enabling attackers to execute malicious actions on behalf of logged-in users. This risk applies to both GET and POST requests, due to the absence of the SameSite attribute on cookies and the ability to refresh cookies. The vulnerability has been addressed through a patch in commit 14acb704891245bf1703ce6296d62112e85aa995.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share