CVE-2025-23600
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Mar 3, 2025
CWE ID 79
Summary
CVE-2025-23600 is a Cross-Site Scripting (XSS) vulnerability affecting the Send to a Friend Addon, version n/a through 1.4.1. The flaw stems from improper neutralization of user input during web page generation. Hackers can exploit this vulnerability by injecting malicious scripts into the add-on, potentially stealing user data or taking control of user sessions. Users are strongly advised to update to the latest version or consider disabling the add-on until a patch is released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.