CVE-2025-23660

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23660 is a newly disclosed vulnerability affecting the Walter Cerrudo MFPlugin, where a Cross-Site Request Forgery (CSRF) weakness is exploited to allow Stored XSS (Cross-Site Scripting) attacks. The MFPlugin, with a version range from n/a to 1.3, is the affected component. This vulnerability enables an attacker to inject malicious scripts into a user's web browser, potentially compromising their session or data. Users are urged to update the plugin to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share