CVE-2025-25146
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-25146 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Songkick Concerts and Festivals from version n/a through 0.9.7. An attacker exploiting this issue can manipulate a user's web session, enabling unauthorized actions such as ticket purchases or account modifications. The victim needs only to visit a specially crafted malicious website while authenticated with the vulnerable application, posing a serious security risk to users. This vulnerability underscores the importance of implementing proper CSRF protection mechanisms in web applications to prevent unintended data modifications or unauthorized actions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.