CVE-2025-30223

CVSS 3.1 Score 9.3 of 10 (high)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 79

Summary

CVE-2025-30223 is a Cross-Site Scripting (XSS) vulnerability affecting the Beego web framework for the Go programming language, prior to version 2.3.6. The issue lies in Beego's RenderForm() function, which fails to properly HTML escape user-controlled data. This flaw allows attackers to inject malicious JavaScript code into websites, potentially leading to session hijacking, credential theft, or account takeover. The vulnerability is significant as developers often assume such high-level functions automatically escape attributes. This flaw is fixed in Beego version 2.3.6.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share