PT-2025-22356 · Rakessh · Ads24 Lite
Mika
·
Published
2025-05-21
·
Updated
2026-01-04
·
CVE-2025-23458
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Rakessh Ads24 Lite versions through 1.0
Fortinet (affected versions not specified)
Description
A Reflected Cross-site Scripting issue exists in Rakessh Ads24 Lite. This allows for improper neutralization of input during web page generation. Fortinet has addressed a zero-day that was actively exploited in attacks targeting FortiVoice, potentially leading to network breaches and remote access for attackers. These attacks have already impacted enterprises.
Recommendations
Update Rakessh Ads24 Lite to a version later than 1.0.
Update Fortinet FortiVoice to the latest available version.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ads24 Lite