CVE-2025-1145

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Feb 11, 2025
Updated: Feb 18, 2025
CWE ID 79

Summary

CVE-2025-1145 is a Reflected Cross-site Scripting (XSS) vulnerability affecting NetVision Information's ISOinsight product. This issue enables unauthenticated attackers to inject and execute malicious JavaScript code in users' browsers, potentially leading to data theft or other malicious activities. Attacks can be carried out through phishing techniques, making it a significant security risk. Users are urged to update their software and implement robust security measures to prevent such attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share