First published: Wed Apr 09 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in ip2location IP2Location World Clock allows Stored XSS. This issue affects IP2Location World Clock: from n/a through 1.1.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
IP2Location World Clock | <=1.1.9 | |
IP2Location World Clock | <=1.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32644 is considered a high severity Cross-Site Request Forgery (CSRF) vulnerability that allows for Stored XSS in IP2Location World Clock.
To fix CVE-2025-32644, update IP2Location World Clock to version 1.2 or later, which addresses this vulnerability.
CVE-2025-32644 affects IP2Location World Clock versions up to 1.1.9.
CVE-2025-32644 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to Stored XSS.
Yes, CVE-2025-32644 can be exploited remotely, allowing attackers to perform unauthorized actions on behalf of the user.