CVE-2025-23720
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 16, 2025
CWE ID 352
Summary
CVE-2025-23720 is a newly discovered Cross-Site Request Forgery (CSRF) vulnerability that affects Mozilla's Web Push service, from an unknown version up to 1.4.0. An attacker can exploit this issue to perform Stored Cross-Site Scripting (XSS) attacks on unsuspecting users. The vulnerability allows an attacker to inject malicious scripts into a victim's web browser, potentially leading to data theft or unauthorized actions. Users are advised to update their Web Push client to the latest version as soon as possible to mitigate the risk of this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.