Stored Cross-site Scripting Vulnerability in Marmoset Viewer by Revolutionart
CVE-2025-23767
What is CVE-2025-23767?
The Marmoset Viewer plugin by Revolutionart is susceptible to a Stored Cross-site Scripting (XSS) vulnerability, which allows attackers to inject malicious scripts that can be executed in the browser of users viewing the affected web pages. This weakness can lead to unauthorized access to sensitive information, user session hijacking, and potentially other malicious actions within the web application. This issue is present in Marmoset Viewer versions up to 1.9.3, making it imperative for users to apply the necessary security measures to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Marmoset Viewer <= 1.9.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved