CVE-2025-25117

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 7, 2025
CWE ID 79

Summary

CVE-2025-25117 is a Cross-site Scripting (XSS) vulnerability affecting Alex Polonski's Smart Countdown FX. The issue lies in the improper neutralization of user input during web page generation. An attacker can inject malicious scripts into the application, exploiting this vulnerability to execute arbitrary code on a user's browser when they view a specially crafted webpage. This flaw puts users at risk of data theft or further exploitation. The vulnerability exists in versions 1.0 through 1.5.5 of the Smart Countdown FX application.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share