CVE-2025-23810

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 352

Summary

CVE-2025-23810 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Igor Sazonov Len Slider. An attacker can exploit this weakness to perform Reflected XSS (Cross-Site Scripting) attacks. The Len Slider software is impacted from an undisclosed version up to and including 2.0.11. This issue enables an attacker to inject malicious scripts into a user's browser when they unknowingly visit a compromised site, potentially stealing sensitive data or taking control of the user's account.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share