CVE-2025-23793

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23793 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Turcu Ciprian Auto FTP, from an unknown version up to 1.0.1. An attacker can exploit this flaw to perform Stored Cross-Site Scripting (XSS) attacks on users, potentially stealing sensitive data or taking control of their accounts. The CSRF vulnerability allows the attacker to submit malicious requests on behalf of the victim, while the Stored XSS issue enables the attacker to inject malicious scripts into the Auto FTP web interface, which are then executed whenever the vulnerable page is accessed by the victim. This combination of vulnerabilities poses a significant risk to users of the affected Auto FTP software.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share