CVE-2025-27332
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Feb 24, 2025
CWE ID 352
Summary
CVE-2025-27332 is a Cross-Site Request Forgery (CSRF) vulnerability discovered in the gmnazmul Smart Maintenance & Countdown application. maliciously crafted requests can manipulate the application on behalf of an unsuspecting user, leading to Stored Cross-Site Scripting (XSS) attacks. The impact of this issue extends from version 1.0 to 1.2 of the Smart Maintenance & Countdown software. Users are strongly advised to upgrade to a patched version or adopt appropriate security measures to protect against CSRF and XSS threats.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- WordPress