CVE-2025-23567

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23567 is a newly disclosed vulnerability affecting Intuitive Design's GDReseller software. The flaw combines a Cross-Site Request Forgery (CSRF) weakness with the potential for Stored XSS (Cross-Site Scripting) attacks. Impacted versions of GDReseller range from n/a to 1.6. An attacker could exploit this CSRF/Stored XSS combination to inject malicious scripts into a user's browser, potentially leading to unauthorized actions or data theft. This issue poses a significant security risk and requires immediate attention from GDReseller users to apply the necessary patches or updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share