CVE-2025-23732

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 22, 2025
CWE ID 79

Summary

CVE-2025-23732 is a Cross-site Scripting (XSS) vulnerability impacting NotFound Easy Filtering versions 2.5.0 and below. The flaw, referred to as an Improper Neutralization of Input During Web Page Generation issue, allows attackers to inject malicious scripts into web pages viewed by other users. These scripts can steal sensitive information, manipulate content, or even take control of the affected system. The vulnerability poses a significant risk to organizations using NotFound Easy Filtering and underscores the importance of maintaining up-to-date software to protect against cyber threats.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share