CVE-2025-24885
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Jan 30, 2025
CWE ID 284
CWE ID 79
Summary
CVE-2025-24885 is a vulnerability affecting the pwn.college cybersecurity education platform. This issue results from missing access controls on rendering custom, unprivileged Dojo pages. Maliciously crafted inputs can lead to Stored Cross-Site Scripting (XSS) attacks, allowing attackers to inject and execute malicious scripts on other users' browsers. Successful exploitation can result in data theft or unauthorized account access. Users are advised to apply patches or updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share