CVE-2025-23431
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Feb 14, 2025
CWE ID 79
Summary
CVE-2025-23431 is a Cross-site Scripting (XSS) vulnerability affecting the NotFound Envato Affiliater from versions n/a through 1.2.4. This issue arises due to improper neutralization of user inputs during web page generation, enabling attackers to inject malicious scripts into web pages viewed by other users. Such scripts can steal user data, manipulate web applications, or launch further attacks. This vulnerability poses a significant risk and requires immediate attention and patching from users to prevent potential security breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share