CVE-2025-23673
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-23673 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Don Kukral Email on Publish software, versions from n/a to 1.5. This issue allows an attacker to execute Stored Cross-Site Scripting (XSS) attacks on unsuspecting users. The CSRF vulnerability enables the attacker to craft malicious requests that appear legitimate, potentially leading to the execution of malicious scripts within the user's browser. The Stored XSS component allows the attacker to inject and permanently save the malicious script within the application, ensuring continued exploitation even after the user leaves the compromised site.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.