CVE-2025-25097
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-25097 is a Cross-site Scripting (XSS) vulnerability affecting the kwiliarty External Video For Everybody software. The issue arises from improper neutralization of user inputs during web page generation. An attacker can exploit this vulnerability to inject malicious scripts into web pages viewed by other users. Successful attacks could result in unintended actions being carried out on affected users' browsers or the theft of sensitive information. This issue affects versions 2.1.1 and below of the External Video For Everybody software. It is recommended that users update to the latest version or take other appropriate measures to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.