CSRF Vulnerability in RAYS Grid by IT-RAYS
CVE-2025-27317
4.3MEDIUM
Key Information:
- Vendor
- It-rays
- Status
- Rays Grid
- Vendor
- CVE Published:
- 24 February 2025
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the RAYS Grid product by IT-RAYS, allowing an attacker to induce users to perform unwanted actions on a web application in which they are authenticated. This specific vulnerability affects versions up to and including 1.3.1, making it critical for users to review their security posture and apply necessary updates to mitigate potential attacks.
Affected Version(s)
RAYS Grid <= 1.3.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Xuan Chien (Patchstack Alliance)