CVE-2025-23617

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23617 is a newly discovered vulnerability affecting the Oliver Schaal Floatbox Plus software. This issue involves a Cross-Site Request Forgery (CSRF) vulnerability that also includes Stored XSS (Cross-Site Scripting) capabilities. The CSRF flaw allows an attacker to force unintended actions from a victim's web browser, while the Stored XSS component enables attackers to inject malicious scripts into web pages viewed by other users. This vulnerability affects versions of Floatbox Plus ranging from n/a to 1.4.4. Users are advised to update to the latest patched version immediately to mitigate the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share