CVE-2025-31566

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 352

Summary

CVE-2025-31566 is a Cross-Site Request Forgery (CSRF) vulnerability discovered in the Rio Video Gallery software. This issue enables an attacker to execute Stored Cross-Site Scripting (XSS) attacks against users. The vulnerability affects all versions of Rio Video Gallery from n/a to 2.3.6. An attacker can exploit this flaw by crafting malicious requests that, when processed by a vulnerable system, injects malicious scripts into web pages viewed by other users, potentially leading to stolen user sessions or sensitive data exposure. It is strongly recommended that users immediately update their Rio Video Gallery installations to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share