CVE-2025-23622

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 24, 2025
CWE ID 79

Summary

CVE-2025-23622 is a Cross-site Scripting (XSS) vulnerability affecting NotFound CBX Accounting & Bookkeeping from versions n/a through 1.3.14. The flaw, which involves improper neutralization of user inputs during web page generation, permits attackers to inject malicious scripts into the targeted system. These scripts can be executed within the context of the web application, leading to unauthorized data access or even complete system compromise. Users are advised to update to the latest version of the software to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share