CVE-2025-39424

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 352

Summary

CVE-2025-39424 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Simple Maps, a mapping tool, from version n/a through 0.98. An attacker exploiting this issue can make unauthorized requests on behalf of a user, potentially leading to data theft or modification, as the application does not properly validate and filter user input, enabling Stored XSS attacks. This flaw poses a significant risk to users interacting with the affected Simple Maps versions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share