CVE-2025-25149
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Feb 7, 2025
CWE ID 352
Summary
CVE-2025-25149 is a newly discovered vulnerability in the Danillo Nunes Login-box, affecting versions from n/a to 2.0.4. This issue combines Cross-Site Request Forgery (CSRF) and Stored XSS (Cross-Site Scripting) attacks. An attacker can exploit the CSRF vulnerability to execute malicious scripts on a user's browser, which are then stored for future use via the Stored XSS component. The consequences can range from data theft to full account takeover. It is essential to upgrade to a patched version of the Login-box as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share