Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 02 Jan 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisa software Acquisition Guide
|
|
| CPEs | cpe:2.3:a:cisa:software_acquisition_guide:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cisa software Acquisition Guide
|
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisa
Cisa software Acquisition Guide Tool |
|
| Vendors & Products |
Cisa
Cisa software Acquisition Guide Tool |
Fri, 12 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. The JavaScript would execute in the context of the user's browser when the user submits the page (clicks 'Next'). | |
| Title | Software Acquisition Guide Supplier Response Web Tool XSS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2025-12-12T20:36:25.597Z
Reserved: 2025-12-09T17:06:11.269Z
Link: CVE-2025-67634
No data.
Status : Analyzed
Published: 2025-12-12T21:15:59.480
Modified: 2026-01-02T18:52:18.527
Link: CVE-2025-67634
No data.
OpenCVE Enrichment
Updated: 2025-12-14T21:15:39Z