CVE-2025-23649
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-23649 is a recently disclosed Cross-Site Request Forgery (CSRF) vulnerability affecting the Kreg Steppe Auphonic Importer. This issue permits attackers to inject Stored Cross-Site Scripting (XSS) code into affected systems. The CSRF flaw, present in versions of Auphonic Importer ranging from n/a to 1.5.1, allows attackers to trick users into executing malicious scripts when they access a specially crafted webpage. Successful exploitation could lead to unauthorized actions or sensitive data exposure. Users are strongly encouraged to update their Auphonic Importer installations as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.