CVE-2025-2124

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 9, 2025
CWE ID 41

Summary

CVE-2025-2124 is a recently disclosed cross-site scripting (XSS) vulnerability affecting Control iD RH iD 25.2.25.0. The issue lies within the API Handler's component in the /v2/customerdb/person.svc/change_password file. A manipulated argument message can lead to XSS, enabling attackers to inject malicious code and potentially gain unauthorized access to user sessions. This vulnerability can be exploited remotely, increasing the threat level. Unfortunately, the vendor was not responsive to early disclosures of this vulnerability, leaving users at risk until a patch is released.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share