CVE-2025-23717

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23717 is a Cross-Site Request Forgery (CSRF) vulnerability identified in the ITMOOTI Theme My Ontraport Smartform. This issue allows an attacker to inject malicious code via Stored XSS (Cross-Site Scripting) attacks. Affected versions of the Theme My Ontraport Smartform range from n/a to 1.2.11, making it essential for users to apply the necessary security patches promptly to mitigate the risk. An attacker can exploit this vulnerability by deceiving a user into clicking a malicious link or performing an unintended action on their behalf, potentially leading to data theft or unauthorized access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share