CVE-2025-0583

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 20, 2025
CWE ID 79

Summary

CVE-2025-0583 is a newly disclosed Reflected Cross-site Scripting (XSS) vulnerability affecting the a+HRD component from aEnrich Technology. An attacker can exploit this issue by crafting a malicious URL and tricking users into visiting it. Upon doing so, the attacker can inject and execute arbitrary JavaScript codes in the users' browsers, potentially stealing sensitive information or taking control of their sessions. This vulnerability poses a significant risk to organizations and individuals who use the a+HRD solution, emphasizing the importance of timely updates and user awareness training.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share