CVE-2025-46233

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Apr 22, 2025
Updated: Apr 30, 2025
CWE ID 79

Summary

CVE-2025-46233 is a Cross-site Scripting (XSS) vulnerability affecting Sirv CDN and Image Hosting. The flaw, which allows Stored XSS attacks, enables malicious actors to inject malicious scripts into Sirv's web pages. Users visiting affected pages may unknowingly execute these scripts, potentially leading to information theft, session hijacking, or other malicious activities. Sirv versions from n/a through 7.5.3 are reportedly vulnerable to this issue. Users are strongly advised to update to the latest version or contact their service provider to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share