Reflected XSS Vulnerability in Mancx AskMe Widget by NotFound
CVE-2025-23718
7.1HIGH
Summary
The Mancx AskMe Widget by NotFound is susceptible to a reflected XSS vulnerability due to improper input handling during web page generation. This vulnerability allows attackers to execute arbitrary JavaScript code in the context of a user's browser session, potentially leading to data theft, session hijacking, or other malicious actions. The issue affects versions of the Mancx AskMe Widget up to 0.3, making it crucial for users to apply necessary updates or mitigations to enhance their website's security.
Affected Version(s)
Mancx AskMe Widget <= 0.3
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)