CVE-2025-46450

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 352

Summary

CVE-2025-46450: A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the x000x occupancyplan, version n/a through 1.0.3.0. An attacker could exploit this issue to inject Stored Cross-Site Scripting (XSS) code into unsuspecting users' browsers. The CSRF flaw allows an attacker to induce targeted users to perform unintended actions, such as modifying their own data, on the occupancyplan web application. This vulnerability poses a risk to users who access the application and could potentially lead to data loss, unauthorized account access, or other malicious activities. It is recommended that users and administrators upgrade to the latest, secure version of occupancyplan to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share