CVE-2025-46514

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 352

Summary

CVE-2025-46514 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Milat jQuery Automatic Popup, version n/a through 1.3.1. An attacker can exploit this flaw to perform malicious actions on behalf of an unsuspecting user, such as modifying their account settings or stealing sensitive information. Additionally, this vulnerability includes a Stored XSS (Cross-Site Scripting) component, allowing an attacker to inject malicious scripts into web pages that the user later visits, potentially leading to serious security breaches and unauthorized access to user data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share