CVE-2025-23690

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23690 is a newly identified vulnerability affecting ArtkanMedia's Book a Place software, specifically versions from n/a to 0.7.1. This issue involves a Cross-Site Request Forgery (CSRF) vulnerability, which enables attackers to perform unintended actions on a user's behalf. Additionally, Stored XSS (Cross-Site Scripting) is present, allowing an attacker to inject malicious scripts that can be executed by other users when they visit a specially crafted website. This combination of vulnerabilities can lead to serious security risks, including data theft and unauthorized system access. Users are strongly advised to upgrade to the latest version of Book a Place to mitigate these risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share