CVE-2025-23499
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 16, 2025
CWE ID 352
Summary
CVE-2025-23499 is a Cross-Site Request Forgery (CSRF) vulnerability identified in the Pascal Casier Board Election software. This issue permits an attacker to execute Stored Cross-Site Scripting (XSS) attacks against unsuspecting users. The affected version range is from n/a to 1.0.1. Successful exploitation of this vulnerability could lead to the injection of malicious scripts into a user's web browser, potentially resulting in data theft or unauthorized actions. Users are advised to upgrade to the latest version of the software to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.