CVE-2025-0795

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Jan 29, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-0795 is a newly disclosed vulnerability in ESAFENET CDG V5. This issue, located in the file /todolistjump.jsp, has been classified as problematic due to its potential for cross-site scripting (XSS) attacks. By manipulating the argument flowId, an attacker can inject malicious code that is executed in a victim's browser. This vulnerability allows for remote attacks, making it a significant security concern. The exploit for this vulnerability has been made public, increasing the risk for potential exploitation. Despite early notification, the vendor has not responded to disclose a patch or mitigation strategy.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share