Cross-Site Scripting Vulnerability in NotFound Legal+ Affects Web Applications
CVE-2025-23835
7.1HIGH
What is CVE-2025-23835?
NotFound Legal+ is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability that arises from improper neutralization of input during web page generation. This flaw allows attackers to inject malicious scripts into dynamic web pages, potentially compromising user interactions and sensitive data. The issue affects all versions of Legal+ up to 1.0, making it essential for users to address this vulnerability to enhance their web application's security.
Affected Version(s)
Legal + <= 1.0