CVE-2025-24561

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 24, 2025
CWE ID 352

Summary

CVE-2025-24561 is a newly disclosed vulnerability that impacts ReviewsTap's software. The flaw involves a Cross-Site Request Forgery (CSRF) issue, which enables attackers to submit malicious requests on behalf of a user. Additionally, ReviewsTap is susceptible to Stored XSS attacks, allowing an attacker to inject malicious scripts into a webpage that is later viewed by other users. This vulnerability affects ReviewsTap versions from n/a through 1.1.2. System administrators and users are strongly advised to upgrade to a patched version or implement other mitigation measures to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share