Cross-Site Request Forgery Vulnerability in Blighty Explorer by Blighty
CVE-2025-27321
7.1HIGH
Key Information:
- Vendor
- Blighty
- Status
- Blightly Explorer
- Vendor
- CVE Published:
- 24 February 2025
Summary
A Cross-Site Request Forgery (CSRF) vulnerability in Blighty Explorer enables attackers to exploit the application, resulting in Stored Cross-Site Scripting (XSS). This vulnerability potentially allows unauthorized actions to be performed on behalf of users, leading to the compromise of sensitive information. Affected versions include Blighty Explorer up to 2.3.0. Users are advised to apply updates and follow best security practices to mitigate risks associated with this vulnerability.
Affected Version(s)
Blightly Explorer <= 2.3.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
johska (Patchstack Alliance)