PT-2025-5910 · Unknown · Vignette Ads

Soprobro

·

Published

2025-02-07

·

Updated

2025-02-12

·

CVE-2025-25071

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Vignette Ads versions n/a through 0.2
Description A Cross-Site Request Forgery (CSRF) issue in Vignette Ads allows Stored XSS. This means an attacker can trick a user into performing unintended actions on the web application, potentially leading to the execution of malicious scripts stored on the server.
Recommendations For versions n/a through 0.2, consider disabling any features that may be susceptible to CSRF attacks until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. Avoid using the application for critical tasks until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-25071

Affected Products

Vignette Ads