CVE-2025-41365
BaseFortify
Publication date: 2025-06-06
Last updated on: 2025-06-06
Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-94 | The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a code injection flaw in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. It allows an attacker who has authenticated access with permissions higher than view to store malicious code in the software, which will then execute in the victim's browser.
How can this vulnerability impact me? :
If exploited, this vulnerability can lead to malicious code running in the victim's browser, potentially compromising the user's data or system. However, exploitation requires authenticated access with elevated permissions, limiting the risk to authorized users with sufficient privileges.