CVE-2025-23865
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-23865 is a Cross-site Scripting (XSS) vulnerability affecting the Winning Portfolio software from version n/a through 1.1. An attacker can inject malicious scripts into the application during the web page generation process, leading to stored XSS attacks. This issue poses a significant risk, as vulnerable web pages can be viewed by any user, potentially allowing attackers to steal sensitive information, manipulate content, or even take control of users' browsers. Successful exploitation could result in serious security breaches and unauthorized access to the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.