CVE-2025-0458

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-0458 is a newly disclosed vulnerability affecting Virtual Computer's Visual RH Solution 2024.12.1. This issue lies in the unknown functionality of the /index.php component's Login Panel, where manipulation of the page argument triggers cross-site scripting (XSS). The attack can be executed remotely, allowing an adversary to inject malicious code into a user's browser. The exploit for this vulnerability has been made public, increasing the risk of widespread exploitation. Despite early disclosure, the vendor has yet to respond to reports of this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share