CVE-2025-24673
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 24, 2025
CWE ID 80
Summary
CVE-2025-24673 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Ketchup Shortcodes developed by AyeCode Ltd. The issue lies in the improper neutralization of script-related HTML tags, allowing attackers to inject malicious scripts into a webpage. This vulnerability, present in versions from n/a through 0.1.2, can result in unintended execution of malicious code on users' browsers, potentially leading to data theft or unauthorized access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- AyeCode Ltd