CVE-2025-1807
CVSS 3.1 Score 3.5 of 10 (low)
Details
Summary
CVE-2025-1807 is a recently disclosed vulnerability affecting Eastnets PaymentSafe 2.5.26.0. The issue lies within the Edit Manual Reply Handler component, specifically in the /directRouter.rfc file. An attacker can exploit this vulnerability by manipulating the Title argument, resulting in a basic cross-site scripting attack. This exploit can be carried out remotely, making it a significant concern. Despite early notification to the vendor, they have yet to respond or issue a patch. As a result, the exploit is publicly available and could potentially be used maliciously.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.