CVE-2025-27290
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 24, 2025
CWE ID 352
Summary
CVE-2025-27290 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the seyyed-amir Erima Zarinpal Donate software. This issue enables malicious actors to submit unintended commands or actions on behalf of an unsuspecting user. The vulnerability exists in versions of the donate platform from n/a through 1.0, potentially putting numerous users at risk. Successful exploitation may lead to unauthorized transfer of funds or other data manipulation. Users are urged to update their software to the latest version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share