PT-2025-12625 · Unknown · Pro Rank Tracker

Abdi Pranata

·

Published

2025-03-24

·

Updated

2025-03-24

·

CVE-2025-30583

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Pro Rank Tracker versions n/a through 1.0.0
Description The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability that allows Stored XSS.
Recommendations For versions n/a through 1.0.0, as a temporary workaround, consider disabling any functionality that may be susceptible to CSRF attacks until a patch is available. Restrict access to potentially vulnerable modules to minimize the risk of exploitation. Avoid using parameters that could be used to inject malicious scripts in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-30583

Affected Products

Pro Rank Tracker