CVE-2025-23616
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-23616 is a Cross-site Scripting (XSS) vulnerability affecting Canalplan, a navigation software for inland waterways. The issue stems from improper input neutralization during web page generation. An attacker can exploit this vulnerability to inject malicious scripts into web pages viewed by other users. Successful attacks could lead to unauthorized access to user data or sessions, potentially resulting in identity theft or other security breaches. Users of Canalplan versions from n/a to 5.31 are at risk. Updating to a patched version is recommended to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.