CVE-2025-23677
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-23677 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the DSmidgy HTTP to HTTPS link changer developed by Eyga.net. The weakness allows an attacker to execute Stored XSS (Cross-Site Scripting) attacks on unsuspecting users. This issue compromises the security of HTTP to HTTPS link changer versions 0.2.4 and below. Attackers can inject malicious scripts into a website, which in turn can be executed on users' browsers when they visit the affected site, potentially leading to data theft or unauthorized access. Users are advised to upgrade to a patched version of the software as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.