Impact
A cross‑site scripting (XSS) flaw exists in the web interface of Proxmox Virtual Environment. By injecting a crafted payload, an attacker can cause the browser to execute arbitrary JavaScript or render arbitrary HTML when a user visits a compromised page or loads a malicious link. This can lead to credential theft, session hijacking, defacement or the ability to run malicious code in the victim’s browser context, potentially affecting confidentiality, integrity or availability of the system.
Affected Systems
This vulnerability affects Proxmox Virtual Environment 9.x 5.1.8 and 8.x 4.3.16. Users running these exact versions should confirm whether upgrades are applicable or whether they remain in use.
Risk and Exploitability
The CVSS v3.1 score of 6.1 indicates moderate severity, but the EPSS score of less than 1% suggests a very low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to deliver or be able to inject the payload through the web UI, although the description does not specify authentication requirements; the attack vector is inferred to be the web interface. Given the moderate impact and low probability of exploitation, this represents a moderate operational risk pending remediation.
OpenCVE Enrichment