CVE-2025-24717

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 24, 2025
CWE ID 352

Summary

CVE-2025-24717 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Modal Window component from Wow-Company. Versions from n/a to 6.1.4 are impacted by this issue. An attacker can exploit this flaw to perform unintended actions on a user's behalf, potentially leading to data theft or unauthorized modifications. The vulnerability arises due to insufficient input validation and fails to implement proper anti-CSRF tokens in the Modal Window functionality.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share