CVE-2025-30546

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 24, 2025
Updated: Mar 27, 2025
CWE ID 352

Summary

CVE-2025-30546 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the boroV Cackle software. This issue permits malicious actors to submit unintended commands or modifications to the affected system on behalf of a user, due to insufficient validation of user input. The vulnerability can be exploited if a user visits a specially crafted website while logged in to Cackle, from versions 4.33 and prior. Successful exploitation could result in unauthorized actions, including account takeover or data modifications. Users are advised to upgrade to the latest version of Cackle and apply additional security measures to mitigate the risk of CSRF attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share