CVE-2025-24318
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Published Feb 28, 2025
CWE ID 1004
Summary
CVE-2025-24318 is a cybersecurity vulnerability affecting web applications. This issue arises due to the cookie policy being observable via built-in browser tools. In certain scenarios, such as Cross-Site Scripting (XSS) attacks, an attacker could exploit this vulnerability to gain access to the user's session information, potentially resulting in full compromise of the user's account. It is crucial for affected organizations to promptly address this vulnerability to prevent potential data breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.