CVE-2025-30900
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-30900 is a Cross-site Scripting (XSS) vulnerability affecting Zoho Billing's Embed Payment Form. The flaw, identified as Improper Neutralization of Input During Web Page Generation, allows attackers to inject malicious scripts into the web pages generated by the form. The vulnerability can be exploited to steal user data or take control of their browsing sessions. Affected versions of Zoho Billing – Embed Payment Form range from n/a to 4.0. Users are advised to upgrade to the latest version and implement input validation and output encoding to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.