CVE-2025-23839
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 24, 2025
CWE ID 79
Summary
CVE-2025-23839 refers to a Cross-site Scripting (XSS) vulnerability discovered in the NotFound Sticky Button. This issue allows an attacker to inject malicious scripts into web pages viewed by other users. The vulnerability is a result of improper neutralization of user input during web page generation. The NotFound Sticky Button, which has a version range from n/a through 1.0, is affected by this issue. Successful exploitation could lead to unintended execution of malicious code in a user's browser, potentially compromising their data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.