CVE-2025-25149

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 7, 2025
CWE ID 352

Summary

CVE-2025-25149 is a newly discovered vulnerability in the Danillo Nunes Login-box, affecting versions from n/a to 2.0.4. This issue combines Cross-Site Request Forgery (CSRF) and Stored XSS (Cross-Site Scripting) attacks. An attacker can exploit the CSRF vulnerability to execute malicious scripts on a user's browser, which are then stored for future use via the Stored XSS component. The consequences can range from data theft to full account takeover. It is essential to upgrade to a patched version of the Login-box as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share