CVE-2025-30847

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Mar 27, 2025
CWE ID 79

Summary

CVE-2025-30847 is a Cross-site Scripting (XSS) vulnerability affecting Ashley Novelist from versions n/a through 1.2.3. An attacker can inject malicious code into a web page generated by Ashley Novelist, which is then executed in a user's browser when they view the affected page. This can lead to unauthorized access to sensitive information or the ability to carry out actions on behalf of the user. The vulnerability arises due to improper neutralization of user input. Stored XSS attacks can persist even after the initial attack vector is removed, posing a significant risk to users until the vulnerability is patched.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share