CVE-2025-31460
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-31460 is a newly identified vulnerability that affects the OmniLeads Scripts and Tags Manager. This issue involves a Cross-Site Request Forgery (CSRF) vulnerability, which can lead to Stored XSS (Cross-Site Scripting) attacks. The CSRF weakness allows an attacker to submit malicious requests on behalf of a user, while the Stored XSS component enables the execution of malicious scripts in a user's browser. The vulnerability impacts versions of OmniLeads Scripts and Tags Manager from n/a through 1.3. Users are strongly advised to apply the necessary patches or updates to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.