CVE-2025-3393

CVSS 2.0 Score 4 of 10 (medium)

Details

Published Apr 8, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-3393 is a newly disclosed vulnerability affecting the mrcen springboot-ucan-admin up to version 5f35162032cbe9288a04e429ef35301545143509. This issue, classified as problematic, is located in the Personal Settings Interface's /ucan-admin/index file. Manipulation of this part can result in cross-site scripting attacks, enabling remote attackers to inject malicious code into users' browsers. Since no versioning information is available for this product, it is unknown which releases are affected or unaffected. Public disclosure of the exploit increases the risk of active attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share