CVE-2025-39455

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 352

Summary

CVE-2025-39455 is a newly discovered vulnerability affecting IP2Location Variables, version n/a through 2.9.5. This issue combines a Cross-Site Request Forgery (CSRF) weakness with the potential for Reflected XSS (Cross-Site Scripting). An attacker, who successfully exploits this vulnerability, can inject malicious scripts into a victim's web browser, potentially leading to data theft or system compromise. The CSRF flaw enables an attacker to forge requests, appearing to originate from the victim, while the Reflected XSS component allows the execution of harmful scripts once the request is processed. Users are advised to update to the latest IP2Location Variables version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share