CVE-2025-28892
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-28892 is a Cross-Site Request Forgery (CSRF) vulnerability discovered in the a2rocklobster FTP Sync software. This issue enables an attacker to execute Stored Cross-Site Scripting (XSS) attacks on unsuspecting users. The FTP Sync product, which has a reported version range of n/a to 1.1.6, is affected by this vulnerability. An attacker can exploit this weakness by tricking a user into visiting a malicious website containing the XSS payload, potentially leading to the theft of sensitive data or session hijacking. Users are advised to upgrade to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress