CVE-2025-25148

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 7, 2025
CWE ID 352

Summary

CVE-2025-25148 is a newly disclosed vulnerability affecting the ElbowRobo software version 1.0.2 and earlier. This issue combines a Cross-Site Request Forgery (CSRF) weakness with the potential for Stored XSS attacks. An attacker can exploit the CSRF vulnerability to force a user into making unintended actions on the attacker's behalf, while the Stored XSS component allows the injection of malicious scripts into web pages viewed by other users. The consequences of this flaw can lead to unauthorized actions or data exposure, posing a significant threat to users of the affected software.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share