CVE-2025-22538

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 352

Summary

CVE-2025-22538 is a newly discovered vulnerability affecting the Ofek Nakar Virtual Bot software. This issue involves a Cross-Site Request Forgery (CSRF) weakness, which allows an attacker to execute unauthorized commands on a victim's browser. Moreover, the vulnerability includes Stored Cross-Site Scripting (XSS), enabling an attacker to inject malicious scripts into web pages, potentially stealing sensitive information or taking control of user sessions. The Virtual Bot software, from an undisclosed version up to 1.0.0, is vulnerable to this issue. Users are advised to update their software as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share