CVE-2025-24722

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Jan 24, 2025
CWE ID 79

Summary

CVE-2025-24722 is a Cross-site Scripting (XSS) vulnerability affecting FAQ Builder AYS from version n/a through 1.7.3. This issue arises due to improper neutralization of user input during the generation of web pages. An attacker can exploit this vulnerability to inject malicious scripts into the targeted webpage, causing unintended execution in the context of the affected user. The consequences of this attack can range from session hijacking to data theft and further system compromise. Users are advised to update their FAQ Builder AYS installations to the latest available version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share