CVE-2025-23444
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-23444 is a Cross-site Scripting (XSS) vulnerability affecting the Nasir Scroll Top Advanced software. The flaw, which allows stored XSS attacks, occurs due to improper input neutralization during web page generation. This weakness can be exploited by attackers to inject and execute malicious scripts in users' browsers, potentially leading to data theft or other unauthorized actions. The vulnerability affects versions of Nasir Scroll Top Advanced from n/a through 2.5. System administrators are recommended to apply the necessary patches or upgrades to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.