CVE-2025-28867

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 11, 2025
Updated: Mar 18, 2025
CWE ID 352

Summary

CVE-2025-28867 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Frontpage category filter in stesvis, from versions n/a through 1.0.2. An attacker can exploit this issue by tricking a user into making unintended actions on the affected website, potentially leading to unauthorized changes or data access. The CSRF vulnerability occurs due to insufficient input validation, allowing malicious requests to be executed on behalf of the victim. This weakness poses a significant risk to user security and data integrity.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share