CVE-2025-24289

NONE EPSS 4.2%
Published Jun 29, 20251y ago · Modified Jun 17, 20262w ago
Find Similar
Published Jun 29, 2025 1y ago
Last Modified Jun 17, 2026 2w ago

Description

A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. The plugin is disabled by default.

Threat Intelligence

EPSS Exploit Probability
4.2% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-352 Cross-Site Request Forgery (CSRF) Authentication

References 1

  • community.ui.com https://community.ui.com/releases/Security-Advisory-Bulletin-048-048/af007d99-bb6d-4368-a12f-75e84de19e8d

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.