First published: Thu Jan 16 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlTi5 AlT Report allows Reflected XSS.This issue affects AlT Report: from n/a through 1.12.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
AlTi5 AlT Report | <=1.12.0 | |
WordPress AlT Report | <=1.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23432 has a critical severity due to its potential for reflected cross-site scripting (XSS) attacks.
To fix CVE-2025-23432, upgrade AlTi5 AlT Report to version 1.12.1 or later.
CVE-2025-23432 affects AlTi5 AlT Report from any version up to and including 1.12.0 and also the WordPress AlT Report up to version 1.12.0.
Yes, CVE-2025-23432 can potentially allow attackers to steal sensitive information through XSS exploits.
While specific exploits are not detailed, the nature of the vulnerability indicates it can be exploited through crafted URLs that execute arbitrary scripts.