CVE-2025-23654

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23654 is a newly disclosed vulnerability that combines Cross-Site Request Forgery (CSRF) and Stored XSS attacks on Twitter Posts. The CSRF weakness allows an attacker to force unintended actions from a user, while the Stored XSS component lets the attacker inject malicious code into the Twitter Post platform. This issue affects Twitter Post versions from n/a to 0.1, potentially impacting a significant user base. An attacker could exploit this vulnerability to execute scripts on unsuspecting users, leading to potential data theft or account takeover.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share