CVE-2025-30511

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 79

Summary

CVE-2025-30511 is a stored Cross-Site Scripting (XSS) vulnerability that allows authenticated attackers to inject malicious code into a plant name value during the addition or editing process. By exploiting the improper sanitization of this input, attackers can execute scripts in the context of the affected website, potentially gaining unauthorized access or stealing sensitive user data. This vulnerability poses a significant risk to organizations that rely on this system, as it enables attackers to bypass authentication and gain persistent access to affected applications. It is crucial that affected organizations address this issue promptly by implementing input validation and output encoding to prevent XSS attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share