PT-2025-25349 · Aveva · Aveva Pi Web Api

Published

2025-06-12

·

Updated

2025-06-12

·

CVE-2025-2745

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVEVA PI Web API versions 2023 SP1 and prior
Description A cross-site scripting issue exists that could allow an authenticated attacker with privileges to create or update annotations, or upload media files, to persist arbitrary JavaScript code. This code will be executed by users who were socially engineered to disable content security policy protections while rendering annotation attachments from within a web browser.
Recommendations For AVEVA PI Web API versions 2023 SP1 and prior, update to a version that includes a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-2745

Affected Products

Aveva Pi Web Api