CVE-2025-31328
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 352
Summary
CVE-2025-31328 is a Cross-Site Request Forgery (CSRF) vulnerability affecting SAP Learning Solution. An attacker can exploit this issue by tricking an authenticated user into sending unintended requests to the server. The vulnerability lies in a GET-based OData function that violates expected behavior, posing a risk to both the confidentiality and integrity of the application without impacting its availability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.