CVE-2025-30223
CVSS 3.1 Score 9.3 of 10 (high)
Details
Summary
CVE-2025-30223 is a Cross-Site Scripting (XSS) vulnerability affecting the Beego web framework for the Go programming language, prior to version 2.3.6. The issue lies in Beego's RenderForm() function, which fails to properly HTML escape user-controlled data. This flaw allows attackers to inject malicious JavaScript code into websites, potentially leading to session hijacking, credential theft, or account takeover. The vulnerability is significant as developers often assume such high-level functions automatically escape attributes. This flaw is fixed in Beego version 2.3.6.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.