Description
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15830 | VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites. |
References
History
Tue, 20 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites. | |
| Title | VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-06-24T07:14:21.027Z
Reserved: 2025-04-16T09:29:46.972Z
Link: CVE-2025-41228
Updated: 2025-05-20T15:33:31.176Z
Status : Deferred
Published: 2025-05-20T15:16:07.943
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-41228
No data.
OpenCVE Enrichment
Updated: 2025-06-23T19:31:59Z
Weaknesses
EUVD