CVE-2025-46514
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-46514 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Milat jQuery Automatic Popup, version n/a through 1.3.1. An attacker can exploit this flaw to perform malicious actions on behalf of an unsuspecting user, such as modifying their account settings or stealing sensitive information. Additionally, this vulnerability includes a Stored XSS (Cross-Site Scripting) component, allowing an attacker to inject malicious scripts into web pages that the user later visits, potentially leading to serious security breaches and unauthorized access to user data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.