CVE-2025-46450
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-46450: A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the x000x occupancyplan, version n/a through 1.0.3.0. An attacker could exploit this issue to inject Stored Cross-Site Scripting (XSS) code into unsuspecting users' browsers. The CSRF flaw allows an attacker to induce targeted users to perform unintended actions, such as modifying their own data, on the occupancyplan web application. This vulnerability poses a risk to users who access the application and could potentially lead to data loss, unauthorized account access, or other malicious activities. It is recommended that users and administrators upgrade to the latest, secure version of occupancyplan to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.