CVE-2025-24711

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 24, 2025
CWE ID 352

Summary

CVE-2025-24711 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Wow-Company Popup Box, from an unknown version up to 3.2.4. An attacker can exploit this issue to perform unintended actions on a user's behalf, potentially leading to data modification or unauthorized access, due to insufficient input validation in the Popup Box component. Users are recommended to update to the latest version of the Popup Box software to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share