CVE-2025-32134

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 79

Summary

CVE-2025-32134 represents a Cross-site Scripting (XSS) vulnerability in KaizenCoders URL Shortify. Affecting versions from n/a to 1.10.4, this issue permits an attacker to inject malicious code into web pages generated by the URL Shortify software. By exploiting this Improper Neutralization of Input vulnerability, an attacker can execute scripts in users' browsers, potentially gaining unauthorized access to sensitive information, and performing actions on behalf of the user. This poses a significant risk to users, emphasizing the importance of patching affected installations promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share