CVE-2025-27910

CVSS 3.1 Score 8 of 10 (high)

Details

Published Mar 10, 2025
Updated: Mar 12, 2025
CWE ID 352

Summary

CVE-2025-27910 is a newly disclosed Cross-Site Request Forgery (CSRF) vulnerability affecting the tianti v2.3 software. This issue, located in the /user/ajax/upd/status component, enables attackers to execute unauthorized and arbitrary operations by sending a specially crafted GET or POST request. Successful exploitation could result in significant impact, including the modification or destruction of data, unauthorized access, or unintended system behavior. Users are strongly encouraged to update their tianti installation to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share