Cross-Site Request Forgery Vulnerability in MSTW League Manager by Mark O'Donnell
CVE-2025-58852
7.1HIGH
What is CVE-2025-58852?
The MSTW League Manager plugin, developed by Mark O'Donnell, is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability that enables attackers to execute unauthorized actions on behalf of authenticated users. This can lead to exploitation of stored cross-site scripting (XSS) vulnerabilities, where malicious scripts may be injected and executed within the context of a legitimate user's session. This critical issue affects versions of MSTW League Manager from n/a through 2.10, posing significant risks to user data and system integrity.
Affected Version(s)
MSTW League Manager <= 2.10