CVE-2025-39593
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-39593 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Ever Accounting, a financial management software. Throughout versions 2.1.5 and older, Ever Accounting is susceptible to CSRF attacks, enabling malicious actors to manipulate user sessions and perform unauthorized actions, such as account transfers or data modification. This issue poses a significant risk to users, as they may inadvertently trigger the malicious request when accessing a compromised website or clicking a malicious link. It is crucial that users and organizations upgrade to the latest, non-vulnerable version of Ever Accounting to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.