Cross-Site Request Forgery Vulnerability in Pro Rank Tracker by ProRankTracker
CVE-2025-30583

7.1HIGH

Key Information:

Vendor
CVE Published:
24 March 2025

What is CVE-2025-30583?

A Cross-Site Request Forgery vulnerability exists in Pro Rank Tracker that could lead to Stored Cross-Site Scripting (XSS). This vulnerability affects versions n/a through 1.0.0 of the product, potentially allowing unauthorized actions to be executed on behalf of users without their consent. Attackers may exploit this flaw to inject malicious scripts, compromising user data and security.

Affected Version(s)

Pro Rank Tracker <= 1.0.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdi Pranata (Patchstack Alliance)
.