CVE-2025-39424
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Apr 17, 2025
CWE ID 352
Summary
CVE-2025-39424 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Simple Maps, a mapping tool, from version n/a through 0.98. An attacker exploiting this issue can make unauthorized requests on behalf of a user, potentially leading to data theft or modification, as the application does not properly validate and filter user input, enabling Stored XSS attacks. This flaw poses a significant risk to users interacting with the affected Simple Maps versions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.