First published: Tue Jan 21 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flashmaniac Nature FlipBook allows Reflected XSS. This issue affects Nature FlipBook: from n/a through 1.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
flashmaniac Nature FlipBook | <=1.7 | |
WordPress 3D FlipBook | <=1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23454 is classified as a reflected Cross-site Scripting (XSS) vulnerability, which can pose significant security risks to affected web applications.
CVE-2025-23454 allows attackers to inject malicious scripts into web pages rendered by the Flashmaniac Nature FlipBook, affecting versions up to and including 1.7.
To mitigate CVE-2025-23454, update Flashmaniac Nature FlipBook to the latest version that includes security patches addressing this vulnerability.
CVE-2025-23454 affects all versions of Nature FlipBook from its initial release up to and including version 1.7.
Yes, CVE-2025-23454 can be exploited during a penetration test to verify the presence of reflected XSS vulnerabilities in web applications using affected versions.