CVE-2025-23690
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-23690 is a newly identified vulnerability affecting ArtkanMedia's Book a Place software, specifically versions from n/a to 0.7.1. This issue involves a Cross-Site Request Forgery (CSRF) vulnerability, which enables attackers to perform unintended actions on a user's behalf. Additionally, Stored XSS (Cross-Site Scripting) is present, allowing an attacker to inject malicious scripts that can be executed by other users when they visit a specially crafted website. This combination of vulnerabilities can lead to serious security risks, including data theft and unauthorized system access. Users are strongly advised to upgrade to the latest version of Book a Place to mitigate these risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.