CVE-2025-46246
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 22, 2025
Updated: Apr 29, 2025
CWE ID 352
Summary
CVE-2025-46246 is a Cross-Site Request Forgery (CSRF) vulnerability affecting CreativeMindsSolutions' CM Answers. This issue allows malicious actors to manipulate a user's session and execute unintended actions on their behalf. The vulnerability can be found in CM Answers versions from n/a through 3.3.3. This CSRF flaw poses a serious security risk as it can lead to unauthorized modifications, and potentially, sensitive data disclosure. Users are strongly advised to update to a patched version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.