Cross-site Scripting Vulnerability in RiceTheme's Felan Framework
CVE-2025-22741
7.1HIGH
What is CVE-2025-22741?
The RiceTheme Felan Framework is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability due to improper neutralization of input during webpage generation. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users, potentially leading to data theft or session hijacking. The affected versions, including 1.1.3 and earlier, should be updated to mitigate this risk.
Affected Version(s)
Felan Framework <= 1.1.3