CVE-2025-23622
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 24, 2025
CWE ID 79
Summary
CVE-2025-23622 is a Cross-site Scripting (XSS) vulnerability affecting NotFound CBX Accounting & Bookkeeping from versions n/a through 1.3.14. The flaw, which involves improper neutralization of user inputs during web page generation, permits attackers to inject malicious scripts into the targeted system. These scripts can be executed within the context of the web application, leading to unauthorized data access or even complete system compromise. Users are advised to update to the latest version of the software to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.