CVE-2025-23754

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 27, 2025
CWE ID 79

Summary

CVE-2025-23754 is a Cross-site Scripting (XSS) vulnerability affecting Ulrich Sossou The Loops, versions from n/a to 1.0.2. The flaw lies in the improper neutralization of user inputs during web page generation. An attacker could exploit this vulnerability by injecting malicious scripts, potentially stealing user data or taking control of their sessions when they visit a specially crafted webpage. This weakness poses a significant risk to users, making it crucial for affected organizations to update their software as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share