CVE-2025-23808
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 16, 2025
CWE ID 352
Summary
CVE-2025-23808 is a Cross-Site Request Forgery (CSRF) vulnerability discovered in Matt van Andel's Custom List Table Example. This issue allows an attacker to execute Reflected XSS (Cross-Site Scripting) attacks on affected users. The vulnerability affects Custom List Table Example versions from n/a through 1.4.1. An attacker can manipulate the user's session to inject malicious scripts, potentially leading to data theft or system compromise. Users of these versions are advised to update to the latest, secure version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.