CVE-2025-28857

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 11, 2025
Updated: Mar 19, 2025
CWE ID 352

Summary

CVE-2025-28857 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Rankchecker.io Integration, from versions n/a through 1.0.9. An attacker can exploit this issue to conduct a Stored Cross-Site Scripting (XSS) attack on an unsuspecting user. This vulnerability enables the attacker to inject malicious scripts into the victim's browser, potentially stealing sensitive information or taking control of their account. The CSRF and Stored XSS weaknesses, when combined, significantly increase the risk of a successful attack. Users are strongly encouraged to update their Rankchecker.io Integration to the latest version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share