CVE-2025-24289
NONE EPSS 4.2%
Published Jun 29, 20251y ago · Modified Jun 17, 20262w ago
Published Jun 29, 2025 1y ago
Last Modified Jun 17, 2026 2w ago
Description
A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. The plugin is disabled by default.
Threat Intelligence
EPSS Exploit Probability
4.2% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-352 Cross-Site Request Forgery (CSRF) Authentication
References 1
- community.ui.com https://community.ui.com/releases/Security-Advisory-Bulletin-048-048/af007d99-bb6d-4368-a12f-75e84de19e8d
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.