CVE-2025-3189

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 862

Summary

CVE-2025-3189 is a stored Cross-Site Scripting (XSS) vulnerability affecting DoWISP, a software product, in versions prior to 1.16.2.50. This issue allows an attacker to inject malicious Javascript code into a user's profile picture in SVG format. Upon viewing the affected profile, the malicious script is executed, potentially leading to unauthorized access to user data or even full account takeover. The vulnerability is significant as it bypasses client-side XSS protection and can impact all users who view the affected profile. It is recommended that users update to the latest version of DoWISP as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share