CVE-2025-29722

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Apr 17, 2025
Updated: Apr 23, 2025
CWE ID 352

Summary

CVE-2025-29722 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Commercify v1.0. This issue grants attackers the ability to execute unauthorized actions on authenticated user accounts. The vulnerability stems from a lack of CSRF protection on sensitive endpoints, enabling potential malicious requests from untrusted sources. Successful exploitation could result in significant data manipulation or unintended system changes. Users and administrators are advised to update to the latest version of Commercify, which includes the necessary security enhancements.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share