CVE-2025-31566
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-31566 is a Cross-Site Request Forgery (CSRF) vulnerability discovered in the Rio Video Gallery software. This issue enables an attacker to execute Stored Cross-Site Scripting (XSS) attacks against users. The vulnerability affects all versions of Rio Video Gallery from n/a to 2.3.6. An attacker can exploit this flaw by crafting malicious requests that, when processed by a vulnerable system, injects malicious scripts into web pages viewed by other users, potentially leading to stolen user sessions or sensitive data exposure. It is strongly recommended that users immediately update their Rio Video Gallery installations to a patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.