CVE-2025-23649

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23649 is a recently disclosed Cross-Site Request Forgery (CSRF) vulnerability affecting the Kreg Steppe Auphonic Importer. This issue permits attackers to inject Stored Cross-Site Scripting (XSS) code into affected systems. The CSRF flaw, present in versions of Auphonic Importer ranging from n/a to 1.5.1, allows attackers to trick users into executing malicious scripts when they access a specially crafted webpage. Successful exploitation could lead to unauthorized actions or sensitive data exposure. Users are strongly encouraged to update their Auphonic Importer installations as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share