CVE-2025-0795
CVSS 3.1 Score 3.5 of 10 (low)
Details
Summary
CVE-2025-0795 is a newly disclosed vulnerability in ESAFENET CDG V5. This issue, located in the file /todolistjump.jsp, has been classified as problematic due to its potential for cross-site scripting (XSS) attacks. By manipulating the argument flowId, an attacker can inject malicious code that is executed in a victim's browser. This vulnerability allows for remote attacks, making it a significant security concern. The exploit for this vulnerability has been made public, increasing the risk for potential exploitation. Despite early notification, the vendor has not responded to disclose a patch or mitigation strategy.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.