CVE-2025-32270

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 352

Summary

CVE-2025-32270 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Broadstreet's Broadstreet platform. This issue permits malicious actors to submit unintended commands or actions on behalf of a victim who is currently authenticated on the targeted website. The vulnerability exists in Broadstreet versions from n/a through 1.51.1, putting numerous users at potential risk. An attacker could exploit this flaw to manipulate user actions, such as changing settings, making unauthorized purchases, or gaining access to sensitive information. It is crucial for users to update their Broadstreet platform to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share