CVE-2025-23869
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 16, 2025
CWE ID 352
Summary
CVE-2025-23869 is a newly disclosed vulnerability affecting Shibu Lijack, also known as CyberJack, and his CJ Custom Content. This issue combines two serious web application security risks: Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS). The CSRF vulnerability allows attackers to manipulate users into performing unintended actions on a website, while the Stored XSS vulnerability enables attackers to inject malicious scripts into web pages viewed by other users. This problem affects CJ Custom Content versions from n/a through 2.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.