CVE-2025-30511
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-30511 is a stored Cross-Site Scripting (XSS) vulnerability that allows authenticated attackers to inject malicious code into a plant name value during the addition or editing process. By exploiting the improper sanitization of this input, attackers can execute scripts in the context of the affected website, potentially gaining unauthorized access or stealing sensitive user data. This vulnerability poses a significant risk to organizations that rely on this system, as it enables attackers to bypass authentication and gain persistent access to affected applications. It is crucial that affected organizations address this issue promptly by implementing input validation and output encoding to prevent XSS attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cloud Applications