CVE-2025-23822

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23822 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Cornea Alexandru Category Custom Fields, with versions from n/a to 1.0 being impacted. This issue enables attackers to perform unintended actions on a user's behalf, potentially leading to data modifications or gaining unauthorized access. As a result, an attacker can manipulate the user's session to execute malicious requests, posing a significant security risk. It is crucial for users to update to the latest version or implement necessary CSRF tokens to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share