CVE-2025-23693
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 16, 2025
CWE ID 352
Summary
CVE-2025-23693 is a newly discovered vulnerability affecting Stanisław Skonieczny Secure CAPTCHA. This issue involves a Cross-Site Request Forgery (CSRF) weakness that permits Stored XSS (Cross-Site Scripting) attacks. The vulnerability exists in Secure CAPTCHA versions from n/a up to and including 1.2. Successful exploitation of this weakness could lead to the injection of malicious scripts into a user's web browser, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.