CVE-2025-23989

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 31, 2025
CWE ID 352

Summary

CVE-2025-23989 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Alessandro Piconi's SabLab Internal Link Builder. This issue enables an attacker to execute malicious requests on a user's behalf, bypassing their authentication and potentially gaining unauthorized access to sensitive information or making unintended changes. The vulnerability is present in versions 1.0 and below of the Internal Link Builder software. Successful exploitation requires the attacker to trick the user into clicking on a maliciously crafted link, making it essential for users to exercise caution when clicking on links, especially from unverified sources. To mitigate this risk, it is recommended that users update their Internal Link Builder software to the latest version, or consider implementing CSRF tokens to secure their web applications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share