CVE-2025-23978
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 31, 2025
CWE ID 352
Summary
CVE-2025-23978 is a newly identified vulnerability that affects the Ninos Ego FlashCounter, a component from an unknown version up to 1.1.8. This issue combines two threats: a Cross-Site Request Forgery (CSRF) weakness and Stored Cross-Site Scripting (XSS). The CSRF vulnerability allows attackers to force unintended actions from a user, while the Stored XSS part allows an attacker to insert malicious scripts into a webpage viewed by other users, potentially leading to data theft or system compromise.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.