CVE-2025-28912

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 11, 2025
CWE ID 352

Summary

CVE-2025-28912 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Custom Dashboard Page, with versions from n/a through 1.0. An attacker can exploit this issue to trick a user into making unintended actions on the dashboard, as their session can be manipulated to perform requests on their behalf. This poses a significant risk to user data and functionality control within the dashboard system. Users are strongly advised to update to a patched version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share