CVE-2025-24717
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 24, 2025
CWE ID 352
Summary
CVE-2025-24717 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Modal Window component from Wow-Company. Versions from n/a to 6.1.4 are impacted by this issue. An attacker can exploit this flaw to perform unintended actions on a user's behalf, potentially leading to data theft or unauthorized modifications. The vulnerability arises due to insufficient input validation and fails to implement proper anti-CSRF tokens in the Modal Window functionality.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.