CVE-2025-25147

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 7, 2025
CWE ID 352

Summary

CVE-2025-25147 is a serious vulnerability affecting the Phillip.Gooch Auto SEO software. This issue combines Cross-Site Request Forgery (CSRF) with Stored Cross-Site Scripting (XSS), allowing attackers to inject malicious scripts into a user's web session. The CSRF vulnerability enables an attacker to perform unauthorized actions on behalf of the user, while the Stored XSS component allows the attacker to persistently inject malicious scripts into a targeted website. This vulnerability affects Auto SEO versions from n/a through 2.5.6. Users are urged to update their software as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share