Cross-Site Request Forgery Vulnerability in Blighty Explorer by Blighty
CVE-2025-27321

7.1HIGH

Key Information:

Vendor
Blighty
Status
Blightly Explorer
Vendor
CVE Published:
24 February 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability in Blighty Explorer enables attackers to exploit the application, resulting in Stored Cross-Site Scripting (XSS). This vulnerability potentially allows unauthorized actions to be performed on behalf of users, leading to the compromise of sensitive information. Affected versions include Blighty Explorer up to 2.3.0. Users are advised to apply updates and follow best security practices to mitigate risks associated with this vulnerability.

Affected Version(s)

Blightly Explorer <= 2.3.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

johska (Patchstack Alliance)
.