Cross-Site Request Forgery Vulnerability in mySCADA myPRO Manager
CVE-2025-23411

5.1MEDIUM

Key Information:

Vendor

Myscada

Vendor
CVE Published:
13 February 2025

What is CVE-2025-23411?

The mySCADA myPRO Manager application is susceptible to cross-site request forgery (CSRF), allowing attackers to exploit the vulnerability by tricking users into visiting a malicious website. This can result in unauthorized actions being performed on behalf of the user, potentially leading to the exposure of sensitive information. It is crucial for users of myPRO Manager to implement diligent security practices to mitigate the risk of CSRF attacks.

Affected Version(s)

myPRO Manager 0 < 1.4

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl reported these vulnerabilities to CISA.
.
CVE-2025-23411 : Cross-Site Request Forgery Vulnerability in mySCADA myPRO Manager