CVE-2025-27912

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 352

Summary

CVE-2025-27912 is a vulnerability affecting Datalust Seq versions before 2024.3.13545. This issue arises due to missing Content-Type validation, leading to Cross-Site Request Forgery (CSRF). The risk is heightened when Entra ID or OpenID Connect authentication is employed, and a user visits a compromised site. Additionally, when username/password or Active Directory authentication is utilized, and the user visits a malicious site under the same effective top-level domain as the Seq server, the vulnerability can be exploited. Successful attacks enable impersonation and the execution of actions in Seq on behalf of the targeted user.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share