CVE-2025-31444

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 28, 2025
CWE ID 352

Summary

CVE-2025-31444 is a newly disclosed vulnerability affecting the youtag ShowTime Slideshow. This issue combines Cross-Site Request Forgery (CSRF) and Stored XSS (Cross-Site Scripting) vulnerabilities. An attacker can exploit the CSRF vulnerability to execute malicious scripts on a victim's browser by tricking them into clicking a specially crafted link. The Stored XSS component allows the attacker to inject and store malicious scripts, which are then executed when the vulnerable page is viewed by other users. This issue affects ShowTime Slideshow versions from n/a through 1.6. Users are strongly advised to update to a patched version as soon as possible to mitigate the risks associated with this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share