CVE-2025-22491
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Published Feb 28, 2025
CWE ID 20
Summary
CVE-2025-22491: A critical vulnerability was identified in the Foreseer Reporting Software (FRS) application's Reporting Hierarchy Management page. This issue allowed user input to go unsanitized, leading to the execution of arbitrary JavaScript in a browser context for all interacting users. This security vulnerability has been addressed and resolved in the latest version 1.5.100 of the FRS software.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.