CVE-2025-24711
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 24, 2025
CWE ID 352
Summary
CVE-2025-24711 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Wow-Company Popup Box, from an unknown version up to 3.2.4. An attacker can exploit this issue to perform unintended actions on a user's behalf, potentially leading to data modification or unauthorized access, due to insufficient input validation in the Popup Box component. Users are recommended to update to the latest version of the Popup Box software to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.