CVE-2025-31449

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 28, 2025
CWE ID 352

Summary

CVE-2025-31449 is a Cross-Site Request Forgery (CSRF) vulnerability affecting The Visitor Counter, version from n/a to 1.4.3. An attacker can exploit this issue to execute Stored Cross-Site Scripting (XSS) attacks on unsuspecting users. The CSRF flaw enables an attacker to craft malicious requests that can be executed when a victim visits a specially crafted webpage. The Stored XSS vulnerability can be used to inject malicious scripts into a webpage viewed by other users, potentially leading to serious security breaches. Users are urged to update their The Visitor Counter software to the latest version to mitigate these risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share