CVE-2025-22499
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-22499 is a Cross-site Scripting (XSS) vulnerability affecting FAKTOR VIER F4 Post Tree, from an unknown version up to 1.1.18. This issue occurs due to improper neutralization of user input during web page generation. An attacker can exploit this vulnerability by injecting malicious scripts into the application, resulting in unintended execution of code in users' browsers. This can lead to the theft of sensitive information or the installation of malware. Users are advised to update their FAKTOR VIER F4 Post Tree installation to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.