CVE-2025-39416

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 352

Summary

CVE-2025-39416 is a newly disclosed vulnerability affecting the Ichi translit it! software. This issue combines a Cross-Site Request Forgery (CSRF) weakness with the potential for Stored Cross-Site Scripting (XSS). The CSRF vulnerability permits attackers to hijack user sessions and execute unintended actions on their behalf. Simultaneously, the Stored XSS component allows adversaries to inject malicious scripts into web pages, potentially stealing sensitive information or taking control of users' devices. The vulnerability spans from versions n/a to 1.6 of the translit it! software.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share