First published: Fri Jan 24 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Gigaom Sphinx allows Reflected XSS. This issue affects Gigaom Sphinx: from n/a through 0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gigaom Sphinx | >undefined | |
WordPress Gigaom Sphinx plugin | <=0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23734 is classified as a reflected Cross-site Scripting (XSS) vulnerability with a medium severity level.
To fix CVE-2025-23734, upgrade Gigaom Sphinx to a version higher than 0.1 that addresses the input sanitization issues.
CVE-2025-23734 allows attackers to execute scripts in the context of users' browsers, potentially leading to data theft or session hijacking.
CVE-2025-23734 affects Gigaom Sphinx from an undefined version through 0.1, as well as the corresponding WordPress Gigaom Sphinx plugin.
Yes, the WordPress Gigaom Sphinx plugin is vulnerable to CVE-2025-23734 if it is version 0.1 or lower.