CVE-2025-2354
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Mar 17, 2025
CWE ID 79
Summary
CVE-2025-2354 is a newly disclosed vulnerability that affects the VAM Virtual Airlines Manager version 2.6.2. This issue lies in an unknown functionality of the file /vam/index.php, where the manipulation of the registry_id/plane_icao/hub_id arguments can lead to cross-site scripting attacks. These attacks can be launched remotely, and the exploit has been made public. Other parameters might also be susceptible to manipulation. Despite early disclosure, the vendor has yet to respond to the issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.