CVE-2025-23841
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 16, 2025
CWE ID 79
Summary
CVE-2025-23841 is a Cross-site Scripting (XSS) vulnerability affecting Nikos M. Top Flash Embed. The issue stems from improper neutralization of user inputs during web page generation. An attacker can exploit this vulnerability to inject malicious scripts into a targeted website. This stored XSS vulnerability exists in versions of Top Flash Embed from n/a through 0.3.4, potentially exposing affected sites to security threats. Users are advised to update their Top Flash Embed installations to the latest, secure version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.