CVE-2025-23818
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-23818 is a newly disclosed vulnerability affecting the More Link Modifier software version 1.0.3 and below. This issue combines Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) vulnerabilities. An attacker, having gained user privileges through a CSRF attack, could inject malicious scripts into a targeted user's web page, resulting in potential information disclosure or session hijacking. The Stored XSS component allows the attacker to execute scripts even after the user has navigated away from the initial compromised page. Users are advised to update their software to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.