CVE-2025-23713

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23713 is a newly identified vulnerability affecting Artem Anikeev's Hack me if you can platform, specifically versions from n/a to 1.2. This issue combines a Cross-Site Request Forgery (CSRF) weakness with Stored XSS (Cross-Site Scripting) capabilities. An attacker could exploit the CSRF vulnerability to execute malicious scripts within a user's browser, potentially leading to unauthorized actions or data theft. The Stored XSS component increases the severity by enabling attackers to inject malicious scripts that persist even after the initial attack, posing a continuous threat to affected users.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share