Cross-Site Request Forgery Vulnerability in MSTW League Manager by Mark O'Donnell
CVE-2025-58852
What is CVE-2025-58852?
The MSTW League Manager plugin, developed by Mark O'Donnell, is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability that enables attackers to execute unauthorized actions on behalf of authenticated users. This can lead to exploitation of stored cross-site scripting (XSS) vulnerabilities, where malicious scripts may be injected and executed within the context of a legitimate user's session. This critical issue affects versions of MSTW League Manager from n/a through 2.10, posing significant risks to user data and system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MSTW League Manager <= 2.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved